
QRLJacking
Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

Vulnerability Patterns Detector for C# and VB.NET

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

CVE-2026-9830 Proof of Concept

REST/JSON API to the Burp Suite security tool.

OWASP Honeypot, Automated Deception Framework.

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

Hidden parameters discovery suite

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Discover hidden parameters in Caido

The WASM Based Security Toolkit for the Web First Paradigm

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.