
theftfuzzer
TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.

TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

A simple CORS misconfiguration scanner

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Cross Origin Resource Sharing MisConfiguration Scanner

Curated catalog of AWS resource types that can be publicly exposed, with CLI commands for creating and auditing public access configurations across…

Hands-on lab demonstrating CVE-2024-38819 Spring Framework path traversal vulnerability with vulnerable and patched Spring Boot deployments for…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

👀 A Kubernetes cluster resource sanitizer

Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Proof-of-concept for CVE-2024-34221: insecure permission vulnerability in SourceCodester Human Resource Management System 1.0 allowing unauthorized…

Validation of best practices in your Kubernetes clusters

Security risk analysis for Kubernetes resources

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

Technical documentation and proof-of-concept for CVE-2025-55462, a CORS misconfiguration in Eramba v3.26.0 allowing cross-origin authentication…