
webpwn3r
Automated web application security scanner detecting and exploiting RCE, SQL injection, and XSS vulnerabilities with WAF bypass payloads and backend…

Automated web application security scanner detecting and exploiting RCE, SQL injection, and XSS vulnerabilities with WAF bypass payloads and backend…

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

Fast XSS scanner for CVE-2025-66470 targeting NiceGUI's ui.interactive_image component. Features batch scanning, 3-check confirmation system, and…

Python-based web crawler and SQL injection vulnerability scanner using dork queries. Supports proxy and automated scanning for security testing.

Lightweight CLI scanner for CVE-2021-31589 that checks single or multiple URLs for the vulnerability, outputting results to a file for bug bounty and…

Web UI and collaboration platform for the Arachni web application security scanner. Manage scans, dispatchers, profiles, users, and export reports in…

Scans web applications for exposed AWS AppSpec YAML files containing sensitive data like API keys and secrets, aiding bug bounty hunters and…

Offensive pentest toolkit combining OSINT, information gathering, SMB brute force, and Metasploit-compatible Meterpreter stagers for Windows/AD…

Multi-threaded web path brute-forcer for discovering hidden files and directories on web servers, with customizable HTTP methods, SOCKS5 proxy…

A utility for detecting webpage inputs and conducting XSS scans.

Automatically run and save ffuf scans for multiple IPs

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

Advanced WordPress vulnerability scanner targeting REST batch route confusion (CVE-2026-63030) and SQL injection (CVE-2026-60137) for automated…

Automated Bash script to detect and scan Vite servers for CVE-2025-30208 from a URL list, with Discord notifications for execution tracking.

Automated vulnerability scanner that detects exposed BeHat configuration files and sends Telegram notifications. Ideal for bug bounty hunters and…

Automated scanner for exposed phpinfo() pages on web servers, designed for bug bounty hunters and security assessments.

Nuclei template for detecting CVE-2024-57378 in Wazuh web interfaces by extracting version strings via HTTP requests and regex matching.

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC