
MyLog4Shell
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It…

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.

Modern alternative to dirbuster/dirb

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

Microsoft FrontPage Extensions Check (shtml.dll)

Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion

BeHat Configuration file leaking

Appspec YML and YAML leaks

This tool is used to find php info page

EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure

SOUND4 Impact/Pulse/First/Eco <=2.x - Information Disclosure

CGI Print ENV leaking

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…