
agentsid-scanner
Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

Scanner for cPanel & WHM authentication bypass (CVE-2026-41940) that detects vulnerable versions via CRLF injection and session manipulation, with…

SSH-MITM - ssh audits made simple

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

SAML2 Burp Extension

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

CyberArk Security Audit

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.

Modlishka. Reverse Proxy.

A reverse proxy like nginx, built on pingora, simple and efficient.