
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Automatic SSTI detection tool with interactive interface


The Swiss Army knife for automated Web Application Testing

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Next generation web scanner

A collection of useful resources for hacking WordPress and it's plugins and themes

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

A security scanner for your LLM agentic workflows


Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Laravel debug mode - Remote Code Execution (RCE)