
CVE-2026-34835-Black-box-Analysis
A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…


[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

The Secure Coding Practices Quick-reference Guide from OWASP

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Next generation web scanner

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

Proof-of-concept exploit for CVE-2024-26026: unauthenticated SQL injection in F5 BIG-IP Next Central Manager API, enabling remote data extraction and…

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.