
brokeCLAUDIA
CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Automated HTTP Request Repeating With Burp Suite

Official Elastic Skills

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

WEB SERVICE SECURITY ASSESSMENT TOOL

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

Node.js SDK for capturing and replaying API calls made to/from your service

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

ChilliCream Nitro GraphQL version 28.0.13 is vulnerable to multiple Stored Cross Site Scripting (XSS) Vulnerabilities

Type-safe HTTP client library for Android and Java, enabling REST API communication with annotation-based request configuration and converter support.

Type-safe HTTP client for Android and Java with annotation-based API binding, converter support, and integration with OkHttp for network…