
LLMMap
Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

An API hooking framework for intercepting and monitoring Windows applications

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.

Exploit for CVE-2016-9177 targeting Spark Java web framework, demonstrating directory traversal vulnerability in version 2.5.1 for security testing…

Exploit for CVE-2018-12542 in Vert.x-Web, a Java web framework. Demonstrates a path traversal vulnerability allowing unauthorized access to static…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

A next-generation crawling and spidering framework.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin