
NucleiFuzzer
Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

User-Agent , X-Forwarded-For and Referer SQLI Fuzzer

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Generic Scanner for Apache log4j RCE CVE-2021-44228

Web application security scanner created by lcamtuf for google - Unofficial Mirror

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

A rapid HTTP downgrade smuggling scanner written in Go.

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

Multi-engine vulnerability scanner with built-in Nuclei Lite, Afrog, and XRay engines. Features asset discovery via FOFA/Shodan, OOB interaction…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

DOM XSS scanner for Single Page Applications