
CVE-2023-31606
Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Advanced HTTP fingerprinting PoC

Automated HTTP Request Repeating With Burp Suite

PyJFuzz - Python JSON Fuzzer

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

Hidden parameters discovery suite

An HTTP client specifically developed for security researchers

Radamsa fuzzer extension for Burp Suite

BurpSuite Standard/Private Collaborator Library

Alexa skill example for Faraday API

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…