
CVE-2026-35616-check
Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

Proof-of-concept exploit for CVE-2026-26012, demonstrating an authenticated organization collection permissions bypass and cipher enumeration in…

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.