
Azure-APIM-Cross-Tenant-Signup-Bypass
Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

A tool to generate and maintain wordlists for Web fuzzing.

An S3 account ID enumeration and bucket discovery tool

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

An implementation of a vulnerable MCP server using mcp-go

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

Script to perform automatic initial web and vulnerability recon

CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

Fast and easy-to-use directory brute-forcer written in Go.

OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

Read-only Python checker that validates CVE-2026-20079 Cisco FMC authentication-bypass behavior by comparing unauthenticated and csm_processes…

Burp Plugin for Secret Matching

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

HackTheBox Devvortex walkthrough covering subdomain fuzzing, Joomla API enumeration, template-based web shell, bcrypt hash cracking, and Apport-CLI…