
vulnhawk
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

OWASP Domain Protect - prevent subdomain takeover

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)


A program for testing WAF functionality

find sensitive data leaking from ServiceNow instances.

Simple JMX RMI scanning tool

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion


Academic purposes only. Attack against Salesforce lightning with guest privilege.
