
smugglefuzz
A rapid HTTP downgrade smuggling scanner written in Go.

A rapid HTTP downgrade smuggling scanner written in Go.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Rust-powered HTTP Request Smuggling Scanner.

A Burp Extension designed to identify argument injection vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Burp Bounty profile for detecting Apache Text4Shell (CVE-2022-42889), an RCE in Commons Text 1.5-1.9, by scanning HTTP requests.

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)