
endsfuzzer
Fuzz a list of domains for specific endpoints

Fuzz a list of domains for specific endpoints

Generates target specific word lists for Fuzzing with fuff

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

Automated web path fuzzing tool that detects hidden directories, files, and endpoints using intelligent language detection, blacklist/whitelist…

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

The script checks Jenkins endpoints for CVE-2024-43044 by retrieving the Jenkins version from the innstance and comparing it against known vulnerable…

Python exploit script for CVE-2020-14882 targeting Oracle WebLogic Server. Executes remote commands via crafted HTTP requests to unauthenticated…

Bash-based proof-of-concept tester for CVE-2026-23550. Checks WordPress modular connector login endpoints for admin cookie issuance and verifies…

Reflected XSS vulnerability disclosure for Yahoo YUI library, with proof-of-concept exploits across multiple PHP endpoints for security testing and…

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Exploit for Apache Tomcat WebSocket vulnerability CVE-2020-13935, allowing testing of WebSocket endpoints for denial-of-service vulnerability.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

PoC for SpringBreak (CVE-2017-8046)

Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.