Example Usage
01 Accounting Desync → most common Critical (37% of all payouts) 02 Access Control → most common High 03 Incomplete Path → missing modifier on a sibling function 04 Off-by-One → boundary operators, index errors 05 Oracle Price → TWAP manipulation, stale prices 06 ERC4626 Vaults → share inflation, rounding attacks 07 Reentrancy → cross-function, cross-contract, read-only 08 Flash Loan → price manipulation, economic attacks 09 Signature Replay → cross-chain replay, missing nonce/chainId 10 Proxy/Upgrade → uninitialized implementation, storage collision
See also
-Ultimate-Cybersecurity-Roadmap
Free
Ultimate Cybersecurity Roadmap (2025 Edition) | Beginner to Advanced Guide | Learn Ethical Hacking, …
Retire.js
Open Source
Detects the use of JavaScript libraries with known vulnerabilities. Available as a CLI tool, browser…
GraphQL Voyager / InQL
Open Source
InQL is a Burp Suite and standalone GraphQL security scanner. Analyzes introspection queries, genera…
NoSQLMap
Open Source
Automated NoSQL injection and database exploitation tool. Targets MongoDB, CouchDB, Redis, and Cassa…
devguard
Free
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage …
Evilginx2
Open Source
Standalone man-in-the-middle attack framework that bypasses 2FA by proxying authentication sessions …