
WuppieFuzz
A coverage-guided REST API fuzzer developed on top of LibAFL

A coverage-guided REST API fuzzer developed on top of LibAFL

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

An intentionally designed broken web application based on REST API.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Go client to communicate with Chaos DB API.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Collaborative application security testing between humans and agents via CLI and MCP