
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

The Swiss Army knife for automated Web Application Testing

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Detect and bypass web application firewalls and protection systems

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

The Offensive Manual Web Application Penetration Testing Framework.

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Network Infrastructure Penetration Testing Tool

Automatic SSTI detection tool with interactive interface

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Tests your WAF with +160 payloads

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Web application vulnerability scanner

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)