
wfuzz
Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for…

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

Proof-of-concept exploit for reflected cross-site scripting (XSS) vulnerability in Trimble TM4WEB <=22.2.0, demonstrating injection via arbitrary URL…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Damn Small XSS Scanner

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

Check list of URLs against Log4j vulnerability CVE-2021-44228