
GPEWebDefender
Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.


Fast and easy-to-use directory brute-forcer written in Go.

A high performance go implementation of Wappalyzer Technology Detection Library

Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Form of the…

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.

Persistent XSS on Comtrend AR-5387un router

Proof-of-concept for authenticated stored cross-site scripting (XSS) vulnerability in Multilaser RE 170 router firmware 2.2.6733, with reproduction…

🕵️♂️ All-in-one OSINT tool for analysing any website

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…