

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

find sensitive data leaking from ServiceNow instances.

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Getting a handle on container security

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Academic purposes only. Attack against Salesforce lightning with guest privilege.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Simple JMX RMI scanning tool

The code for personally reproducing the corresponding vulnerability

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion