
authelia
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Securely and anonymously share files, host websites, and chat with friends using the Tor network

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

MCP server for Google search and page fetching using headless Chromium

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

OWASP Web Recon & Directory Discovery Platform

Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…


Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public…

HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.