
CVE-2025-12101-Scanner-PoC
Multi-threaded scanner for CVE-2025-12101, a reflected XSS in Citrix NetScaler, with single/multi-host scanning, dual protocol testing, proxy…

Multi-threaded scanner for CVE-2025-12101, a reflected XSS in Citrix NetScaler, with single/multi-host scanning, dual protocol testing, proxy…

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

A PHP CGI Vulnerability Scanner for CVE-2024-4577

SPIP (CMS) Scanner for penetration testing purpose written in Python

Non-intrusive remote checker for pre-authentication RCE chains in WordPress, performing version fingerprinting and vulnerable REST route detection…

Nuclei template for detecting CVE-2025-31324 in SAP NetWeaver. Performs HTTP GET requests to identify vulnerable instances and assess exposure to…

Detects HTML injection and cross-site scripting (XSS) vulnerabilities in web applications, providing targeted security assessment for CVE-2023-3971.

Automated web vulnerability scanner with SQL injection, XSS, command injection, directory traversal, file inclusion detection, plus port scanning,…

OWASP Web Recon & Directory Discovery Platform

Free web-application vulnerability and version scanner

Finds CSP report urls and tests to see if they are vulnerable to log4j

Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure

SOUND4 Impact/Pulse/First/Eco <=2.x - Information Disclosure

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

Multi-threaded Windows security scanner that performs port scanning, service banner grabbing, weak password detection, and vulnerability checks…

Multi-threaded Python scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813 by testing arbitrary file upload via HTTP PUT and…