
Detect_polyfill_CVE-2024-38537-
Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

A modern vulnerable web app

Application scanning component of purpleteam

Web app authorisation coverage scanning

A fast, simple, recursive content discovery tool written in Rust.

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

The AI toolkit for building reliable browser automations

Tests your WAF with +160 payloads

A Burp Extension designed to identify argument injection vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Executable security regression testing for agentic applications and MCP-integrated systems.

find sensitive data leaking from ServiceNow instances.

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Alexa skill example for Faraday API

PoC and detection guide for the critical unauthenticated RCE in IBM Langflow OSS, covering the auto_login token bypass and unsafe /validate/code…

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…