
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Rust-powered HTTP Request Smuggling Scanner.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Http request smuggling vulnerability scanner

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Ruby command-line interface to Burp Suite's REST API

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Application scanning component of purpleteam

A Burp Extension designed to identify argument injection vulnerabilities.

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing