



Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

CVE-2018-25031 tests

API Scraper Agent for Web API's

Burp extension for wordpress security scanning

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

OAuth Request Crafter

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

