#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

BDU:2023-05144 Nuclei checker

To find HTML injection and XSS

Safely detect Citrix NetScaler SAML auth bypass CVE-2026-19490

Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web…

Fast and easy-to-use directory brute-forcer written in Go.

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

Web Application Security Scanner Framework

Gryffin is a large scale web security scanning platform.

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

massive SQL injection vulnerability scanner

RiskScanner 是开源的多云安全合规扫描平台,基于 Cloud Custodian 和 Nuclei 引擎,实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

SQL Vulnerability Scanner

A fast DOM based XSS vulnerability scanner with simplicity.

WPScan rewritten in Python + some WPSeku ideas

BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application. This tool was originally developed by Shawar Khan in CLI.…