engn33r / awesome-redos-securityLinks
List of RegEx DoS (ReDoS) CVEs and resources
☆28Updated 2 years ago
Alternatives and similar repositories for awesome-redos-security
Users that are interested in awesome-redos-security are comparing it to the libraries listed below
Sorting:
- a repository of all the CTF challenges I've made for public events☆58Updated 3 months ago
- Same Origin XSS challenge☆64Updated 3 years ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆58Updated 6 months ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Prototype Pollution exploits collection☆34Updated 4 years ago
- Client-Side Prototype Pollution Tools☆85Updated 4 years ago
- A tool which helps identifying client-side prototype polluting libraries☆39Updated 6 months ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆56Updated last month
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆53Updated 2 years ago
- A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻☆126Updated 3 years ago
- PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution☆19Updated last year
- ☆56Updated 4 years ago
- ☆72Updated 4 years ago
- Here i will post my writeups :)☆33Updated 2 years ago
- Dependency Confusion Security Testing Tool☆51Updated 3 years ago
- Find all libraries on cdn.js that pollute your prototype☆19Updated 3 years ago
- XS-Leaks Wiki☆169Updated 5 months ago
- This repo contains solution for ctf challenges☆37Updated 11 months ago
- A curated list of awesome browser security learning material.☆145Updated 3 years ago
- ☆23Updated 8 months ago
- Challenges I wrote for various CTF competitions☆44Updated last year
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆28Updated 4 years ago
- Content-Security-Policy (CSP) Bypass Techniques☆70Updated 5 years ago
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆28Updated 7 years ago
- PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509☆58Updated 4 years ago
- ☆84Updated last year
- List of Trusted Types bypasses☆102Updated last year
- A cheatsheet for exploiting server-side SVG rasterization.☆30Updated 3 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 6 months ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆59Updated 7 months ago