
gotestwaf
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

BoB Web Application Security Project

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Lightweight Python scanner for detecting stored XSS (CVE-2025-0054) in SAP NetWeaver Java. Submits customizable payloads and checks for script…

:new: The Multi-Tool Web Vulnerability Scanner.

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

Go Web Application Penetration Test

cve-2025-55182

A tool to automate penetration tests

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…