
grafana-CVE-2018-15727
a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

CyberArk Security Audit

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

SAML2 Burp Extension

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A proxy for net.tcp-based WCF traffic.

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…
