
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

CVE-2026-60206 PoC: SAML authentication bypass exploit for Oracle WebLogic with multiple payload modes (XSW, unsigned, NameID) for penetration…

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Intercept, inspect, and manipulate net.tcp-based WCF traffic with TLS and NTLM support. Decodes binary SOAP to XML for logging or HTTP proxy relay,…

Burp Suite extension for testing SAML infrastructures. Manipulate SAML messages, perform signature spoofing, XSW, XXE, and XSLT attacks, and manage…

Remote PowerShell-based security audit tool for CyberArk PAM platforms. Performs CIS benchmark compliance, CVE checks, blackbox testing, and network…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…