
Vega
Open-source web application security scanner with automated vulnerability detection, proxy interception, and SSL/TLS testing for penetration testers…

Open-source web application security scanner with automated vulnerability detection, proxy interception, and SSL/TLS testing for penetration testers…

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Open-source DAST proxy with agentic AI for intercepting, modifying, and replaying HTTP/HTTPS traffic. Automates web application security testing via…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Proof-of-concept exploit demonstrating cross-site scripting (XSS) in Squid Proxy 3.5.27 via malicious X.509 certificate commonName field, with Docker…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Web application firewall testing tool with 344+ attack payloads, auto WAF detection, bypass techniques, and full reconnaissance including DNS,…

a Damn Vulnerable Serverless Application

An intentionally designed broken web application based on REST API.

Deliberately vulnerable C# API application for practicing web application security testing, exploitation techniques, and vulnerability analysis in a…

GUI Burp Plugin to ease discovering of security holes in web applications

Collaborative application security testing between humans and agents via CLI and MCP

Apache Struts application intentionally packed with realistic, complex vulnerabilities for security training and penetration testing practice,…

Proof-of-concept exploit for CVE-2015-9251, demonstrating a specific web application vulnerability with minimal code for testing and verification.

Security advisory and PoC for HTTP request smuggling (CVE-2026-67181) due to Transfer-Encoding desynchronization in rouille's proxy module.