
raider
OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Exploit for CVE-2016-9177 targeting Spark Java web framework, demonstrating directory traversal vulnerability in version 2.5.1 for security testing…

An API hooking framework for intercepting and monitoring Windows applications

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

a Damn Vulnerable Serverless Application

End to End testing of Web, API, Cloud, Events and Security

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…