
raider
OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

SAML2 Burp Extension

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

Penetration tests guide based on OWASP including test cases, resources and examples.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

CyberArk Security Audit

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.