
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automatic SQL injection and database takeover tool

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.


Automated Αll-in-One OS command injection exploitation tool.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A fast, simple, recursive content discovery tool written in Rust.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).