
CVE-2026-34910-PoC
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Burp Suite extension to perform Kerberos authentication

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

SAML2 Burp Extension


SAML2 Burp Extension

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

CyberArk Security Audit

A proxy for net.tcp-based WCF traffic.

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.