
ClaimJumper
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

Time-based blind SQL injection proof-of-concept for LiteLLM v1.65.4. Exploits the `/key/block` endpoint to extract database contents and read server…

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Proof-of-concept exploit for an authorization flaw in Open WebUI that lets low-privileged users edit and delete other members' channel messages via…

Write-ups from completed TryHackMe rooms — Linux privilege escalation, sudo buffer overflow (CVE-2019-18634), and OWASP Top 10 (2025).

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Global API Integrity Assessor

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

A modern vulnerable web app


OWASP Domain Protect - prevent subdomain takeover

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Damn Vulnerable C# Application (API)