
CVE-2025-61148
The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Global API Integrity Assessor

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Server scanning component of purpleteam

A modern vulnerable web app

CLI component of purpleteam

ExtendedMacro - BurpSuite plugin providing extended macro functionality

REST/JSON API to the Burp Suite security tool.

Web app authorisation coverage scanning

Python API security testing tool from OpenStack Security Group

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…