
ParamFinder
Discover hidden parameters in Caido

Discover hidden parameters in Caido

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

CVE-2023-23752 nuclei template

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

Insecure Permissions WeDayCare

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…