
BWASP
BoB Web Application Security Project

BoB Web Application Security Project

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

:new: The Multi-Tool Web Vulnerability Scanner.

A fast DOM based XSS vulnerability scanner with simplicity.

Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.

Lightweight Python scanner for detecting stored XSS (CVE-2025-0054) in SAP NetWeaver Java. Submits customizable payloads and checks for script…

Official Kali Linux tool to check all urls of a domain for SQL injections :)

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

A tool to automate penetration tests

Searcher for cross-site leaks (XS-Leaks)

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

Desktop-based vulnerability assessment tool for security teams — scan web apps & networks, detect CVEs, map exploits, auto-score risk, and generate…

A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.

🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted…

Bash-based scanner that enumerates Grafana plugin IDs and tests for CVE-2021-43798 directory traversal by attempting to read /etc/passwd or win.ini…

Scans web applications for CVE-2024-24919 vulnerabilities via CLI, supporting a single target or wordlist-based bulk URL scanning.