
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

AI-driven vulnerability discovery and live validation

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Multi-engine DAST scanner aggregating Nikto, ZAP, Nuclei, SkipFish, and Wapiti for automated web injection vulnerability detection with consolidated…

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

Model Context Protocol server for autonomous vulnerability discovery

client-side prototype pullution vulnerability scanner

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).