
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Open Source Vulnerability Management Platform

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automatic SQL injection and database takeover tool

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

A next-generation crawling and spidering framework.

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

[CVE-2020-17518] Apache Flink RESTful API Arbitrary File Upload via Directory Traversal

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

GraphQL vulnerability disclosure: CVE-2023-26144

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…