
Ni8mare
Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0)…

Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0)…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

MAPS cloud scanner and response parser for Microsoft Defender research.

An API hooking framework for intercepting and monitoring Windows applications