
CVE-2026-9198
PoC and detection guide for the critical unauthenticated RCE in IBM Langflow OSS, covering the auto_login token bypass and unsafe /validate/code…

PoC and detection guide for the critical unauthenticated RCE in IBM Langflow OSS, covering the auto_login token bypass and unsafe /validate/code…

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

Application scanning component of purpleteam

Web vulnerability scanner written in Python3

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

An intentionally designed broken web application based on REST API.

Tests your WAF with +160 payloads

An strace-like program for the Windows 'native' API


SAML2 Burp Extension

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

A rapid HTTP downgrade smuggling scanner written in Go.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.