


Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI


Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain


Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10




Research on GraphQL from an AppSec point of view.

A modern vulnerable web app

Tests your WAF with +160 payloads

An intentionally designed broken web application based on REST API.

SAML2 Burp Extension