
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…


Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

The Swiss Army knife for automated Web Application Testing

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2

Automatic SSTI detection tool with interactive interface

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Tests your WAF with +160 payloads

Burp Extension for collaboration in Faraday

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)
