
graphw00f
GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Official Kali Linux tool to check all urls of a domain for SQL injections :)

Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.

Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 ,…

JavaScript-based enumeration tool for web filtering proxies and policies. Conducts drive-by tests to reveal products, versions, HTTPS inspection…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

Tool to discover paths in web applications

Termux-based penetration testing toolkit integrating Metasploit, Nmap, SQLmap, and custom modules for payload generation, network scanning, web…

:new: The Multi-Tool Web Vulnerability Scanner.

Subdomain reconnaissance platform with HTTPX live-host probing, MongoDB-backed storage, searchable UI, and Nuclei vulnerability scanning with Discord…

Searcher for cross-site leaks (XS-Leaks)

Automated vulnerability scanner for Vite dev servers, detecting CVE-2025-30208, CVE-2025-31125, and CVE-2025-32395 via FOFA or CIDR target collection…

Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.

Simple scanner to detect vulnerable Livewire installations.

Scans WordPress sites for a specific plugin vulnerability (CVE-2024-10508), checks version 6.0.2.6, and saves vulnerable URLs to a file for reporting.