
CVE-2025-51867
Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

API-based scanner that retrieves and lists the latest Common Vulnerabilities and Exposures (CVEs) for automated security assessment and vulnerability…

Proof-of-concept exploit for CVE-2024-50633, a Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9–v3.3.2, enabling unauthorized…

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

GraphQL automated security testing toolkit

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Burp Suite extension that uses AI-generated regex strike rules to detect IDOR and access-control flaws, then scans proxy history to find similar…

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Go client to communicate with Chaos DB API.

MAPS cloud scanner and response parser for Microsoft Defender research.