
OAUTHScan
Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

The collaborative web app pentest suite

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Discover hidden parameters in Caido

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

Insecure Permissions WeDayCare

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`),…