
SAMLRaider
SAML2 Burp Extension

SAML2 Burp Extension

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Awesome information for WebSockets security research

Faster xss scanner,support reflected-xss and dom-xss

Exploit for CVE-2022-22947: remote code execution in Spring Cloud Gateway via crafted requests to the Actuator endpoint. Includes Python script and…

GUI Burp Plugin to ease discovering of security holes in web applications

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

A rapid HTTP downgrade smuggling scanner written in Go.

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

CVE-2025-30208-EXP

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities