
mzap
⚡️ Multiple target ZAP Scanning

⚡️ Multiple target ZAP Scanning

Ruby command-line interface to Burp Suite's REST API

Collaborative application security testing between humans and agents via CLI and MCP

CyberArk Security Audit

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Simple JMX RMI scanning tool

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Insecure Permissions WeDayCare

SQL Injection in 3CX CRM Integration

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10