
faraday_burp
Burp Extension for collaboration in Faraday

Burp Extension for collaboration in Faraday

PoC and verification toolkit for CVE-2026-28286, an arbitrary file write vulnerability in ZimaOS, exploiting API misconfiguration to write files…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…


find sensitive data leaking from ServiceNow instances.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

Research on GraphQL from an AppSec point of view.

Burp Commander written in Go

The collaborative web app pentest suite

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…