
mcp-server
MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

ChilliCream Nitro GraphQL version 28.0.13 is vulnerable to multiple Stored Cross Site Scripting (XSS) Vulnerabilities

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

☸The first ever dependency-aware GraphQL API testing tool!

XSS Test Swagger 3.14.1 to 3.37.0

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Python API security testing tool from OpenStack Security Group

AI-powered bug bounty hunting toolkit that works with or without subscription.