#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

Next generation web scanner

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

Hack the World using Termux

The Swiss Army knife for automated Web Application Testing

Web vulnerability scanner written in Python3

XSS spider - 66/66 wavsep XSS detected

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

A wrapper around grep, to help you grep for things

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

A modular vulnerability scanner with automatic report generation capabilities.

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Curated list of open-source web security scanners, including general-purpose scanners, infrastructure scanners, and fuzzers, ordered by GitHub stars.