
Http11Probe
An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

A coverage-guided REST API fuzzer developed on top of LibAFL

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Exploits CVE-2026-64849 in MLflow, providing a proof-of-concept attack for security researchers to validate vulnerable deployments.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Collaborative application security testing between humans and agents via CLI and MCP

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Proof-of-concept exploits for CVE-2026-56197 demonstrating remote code execution in Windows Admin Center, implemented in Python for vulnerability…

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Proof-of-concept exploit for the Apache Struts JSON plugin denial-of-service vulnerability (CVE-2026-73633), demonstrating CPU and memory exhaustion…

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…