
api_wordlist
A wordlist of API names for web application assessments

A wordlist of API names for web application assessments

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db

Automatic SSTI detection tool with interactive interface


CVE-2020-6308 mass exploiter/fuzzer.

Simple python script to fuzz site for CVE-2017-9805

CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI

A structure-aware JSON fuzzer

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

Command Injection Web Fuzzer Script for mitmproxy

The Offensive Manual Web Application Penetration Testing Framework.

Tools for auditing WAFS