
crlfi-scanner
CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Tool to discover paths in web applications

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Python3 vulnerability scanner that fuzzes all URLs of a target website and scans them for web vulnerabilities, with optional GoBuster integration for…

Appspec YML and YAML leaks

Spring Cloud Gateway repository demonstrating CVE-2022-22947 exploitation for API security testing and vulnerability analysis.

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

Gryffin is a large scale web security scanning platform.

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

A fast DOM based XSS vulnerability scanner with simplicity.

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.