
httpx
Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

Fast and easy-to-use directory brute-forcer written in Go.

automated web assets enumeration & scanning [DEPRECATED]

Detection for CVE-2025-53072 + CVE-2025-62481

An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.

To find HTML injection and XSS

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Vulnerability detection scripts for the n8n product.

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Web Application Security Scanner

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Multi-threaded scanner for CVE-2025-12101, a reflected XSS in Citrix NetScaler, with single/multi-host scanning, dual protocol testing, proxy…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.