
CVE-2026-35616-check
Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

CLI component of purpleteam

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Stage two containers

Proof-of-concept exploit for CVE-2026-26012, demonstrating an authenticated organization collection permissions bypass and cipher enumeration in…

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Twitter vulnerable snippets

Getting a handle on container security

The DevSecOps toolset for REST APIs

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Python API security testing tool from OpenStack Security Group

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Http request smuggling vulnerability scanner

The dependency-check repository has moved:

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

A Burp Extender plugin, that will make binary soap objects readable and modifiable.