
WuppieFuzz
A coverage-guided REST API fuzzer developed on top of LibAFL

A coverage-guided REST API fuzzer developed on top of LibAFL

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Research on GraphQL from an AppSec point of view.

Proof-of-concept exploit for CVE-2026-68929, demonstrating unauthenticated cross-tenant takeover of FastGPT WeChat channels via public shareId,…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

An on-path blackbox network traffic security testing tool

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

An intentionally designed broken web application based on REST API.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Burp Plugin to decrypt AES encrypted traffic on the fly

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…