
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

A Web Vulnerability Scanner and Patcher

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

Optiva-Framework 🔎 Web Application Scanner🕵️

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

Web Application Vulnerability Scanner.

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

CVE-2025-26054

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Test application for CVE-2025-29927, designed for security study groups to demonstrate and verify the web vulnerability in a controlled environment.

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…

Project dedicated to fight Layer 7 DDoS with proof of work, with an additional WAF and controller. Completed with full set of features and…

Modular web vulnerability scanner with template-driven detection engine for automated testing of XSS, SQLi, LFI, RFI, and sensitive file/directory…