
fuzzdb
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Demystifying Exploitable Bugs in Smart Contracts

Trail of Bits Testing Handbook - appsec.guide

A GUI-based tool to perform security testing against the HDMI CEC (Consumer Electronics Control) and HEC (HDMI Ethernet Channel) protocols

TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.

All Security Resource Collections Repos That I Published.

CVE-2026-5172: buffer overflow in extract_addresses() on crafted resource record PoC

CVE-Candidate: DoS in [email protected] via comma-separated brace expansion (CVE-2024-4068 incomplete fix)

Proof-of-concept exploit for CVE-2024-27316, an HTTP/2 CONTINUATION flood vulnerability in Apache httpd, demonstrating resource exhaustion via…