
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Automatic SSTI detection tool with interactive interface


NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Next generation web scanner

A collection of useful resources for hacking WordPress and it's plugins and themes

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.


Laravel debug mode - Remote Code Execution (RCE)

A wrapper around grep, to help you grep for things

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

GUI Burp Plugin to ease discovering of security holes in web applications

Acunetix 0day RCE