
CVE-2026-9830
CVE-2026-9830 Proof of Concept

CVE-2026-9830 Proof of Concept

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

MCP server for Slither static analysis of Solidity smart contracts

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Scanner: CVE-2026-42208 LiteLLM SQL Injection — Python scanner for BerriAI LiteLLM proxy instances

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Automatic SQL injection and database takeover tool


Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…