
godirb
Fast and easy-to-use directory brute-forcer written in Go.

Fast and easy-to-use directory brute-forcer written in Go.

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

AI-powered bug bounty hunting toolkit that works with or without subscription.

A wrapper around grep, to help you grep for things

Web vulnerability scanner written in Python3

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Scanner for CVE-2024-40725 Apache HTTP Server source-code disclosure; probes direct and subrequest paths, fingerprints affected versions, and outputs…

Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template