
nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

CyberArk Security Audit

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Vulnerability Assessment Scanner with Report Generation

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Script to audit GitHub Action Workflow files for potential vulnerabilities.

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444