
vigolium
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

A proxy for net.tcp-based WCF traffic.

SAML2 Burp Extension

CyberArk Security Audit

Demonstrates exploitation and mitigation of CVE-2024-10924, an authentication bypass in WordPress Really Simple Security, with automated Python…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Proof-of-concept demonstrating lack of rate limiting on the Sylius v2.0.2 login endpoint, enabling unrestricted automated authentication attempts.

Burp Suite extension to perform Kerberos authentication

Oracle E-Business Suite <=12.2 - Authentication Bypass

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…