
CVE-2023-44487
Non-invasive HTTP/2 vulnerability scanner for CVE-2023-44487 that detects exploitable stream reset conditions by testing protocol downgrade and…

Non-invasive HTTP/2 vulnerability scanner for CVE-2023-44487 that detects exploitable stream reset conditions by testing protocol downgrade and…

SQLi scanner to detect SQL vulns

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

HTTPoxy Exploit Scanner by 1N3 @CrowdShield

Script to test if a server is vulnerable to the JetLeak vulnerability

Proof-of-concept scanner for the Optionsbleed vulnerability (CVE-2017-9798) that tests Apache HTTP servers for memory leak via HTTP OPTIONS method.

A Burp Extension to test applications for vulnerability to the Web Cache Deception attack

Time-based blind SQL injection detection tool for recon and bug bounty. Accepts single URLs or lists, supports custom headers, proxy, and POST data…

Text4Shell scanner for Burp Suite

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

XXRF Shots - Useful for testing SSRF vulnerability

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

LaravelN00b .env Scanner

Scanner For Nginx - Remote Integer Overflow Vulnerability

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

Go-based scanner for Apache Tomcat AJP file read/inclusion vulnerability (CVE-2020-1938). Detects and exploits Ghostcat to read arbitrary files or…

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection