
CVE-2026-9830
CVE-2026-9830 Proof of Concept

CVE-2026-9830 Proof of Concept

Discover hidden parameters in Caido

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Zap Extension for collaboration in Faraday

PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

PoC de CVE-2026-35616: control de acceso indebido en FortiClient EMS.

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Metlo is an open-source API security platform.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.