
wp2shell-rce
WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

JavaScript-based enumeration tool for web filtering proxies and policies. Conducts drive-by tests to reveal products, versions, HTTPS inspection…

Automated vulnerability scanner for Vite dev servers, detecting CVE-2025-30208, CVE-2025-31125, and CVE-2025-32395 via FOFA or CIDR target collection…

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for…

Scans WordPress sites for a specific plugin vulnerability (CVE-2024-10508), checks version 6.0.2.6, and saves vulnerable URLs to a file for reporting.

Python-based GUI tool for automated detection of Cross-Site Scripting (XSS) vulnerabilities in web applications using payload injection and response…

Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.

CLI tool to detect CGI printenv information disclosure vulnerability in web servers. Scans single URLs or lists, supports Telegram alerts and output…

Automated reconnaissance and vulnerability scanning shell script for bug bounty hunters. Performs passive/active recon, subdomain enumeration, port…

Automated web reconnaissance tool with dork scanning, SQLi/XSS detection, port scanning, admin panel discovery, and WAF/captcha bypass capabilities.

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

:new: The Multi-Tool Web Vulnerability Scanner.

Subdomain reconnaissance platform with HTTPX live-host probing, MongoDB-backed storage, searchable UI, and Nuclei vulnerability scanning with Discord…

Simple scanner to detect vulnerable Livewire installations.

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

Tool to discover paths in web applications

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…