
FDsploit
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Scan for and exploit CVE-2024-24919 in Check Point Security Gateways, an unauthenticated arbitrary file read that can expose credentials and lead to…

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

This tool is used to find php info page

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu…

A comprehensive Python-based security tool for file scanning, malware detection, and analysis in an ever-evolving cyber landscape.

The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.

Automated data harvesting tool for extracting sensitive information (backups, clones, address books) from web servers via targeted scanning and…

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

Tools and Techniques for Blue Team / Incident Response

The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489

Nuclei Template for CVE-2022-1388

File upload vulnerability scanner and exploitation tool.

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]