
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Web vulnerability scanner written in Python3

AI-powered bug bounty hunting toolkit that works with or without subscription.


Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic SQL injection and database takeover tool

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

automated web assets enumeration & scanning [DEPRECATED]

An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.

To find HTML injection and XSS

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A wrapper around grep, to help you grep for things

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…