#1
面向授权教育行业的侦察与分类编排工具(nmap/dirsearch/sqlmap/hydra + CVE-2024-4577、密钥/API密钥泄露、XSS、wp2shell),带Web控制面板

快速且易于使用的目录暴力破解工具,使用 Go 编写。

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

AI-powered bug bounty hunting toolkit that works with or without subscription.

一个 grep 的包装器,帮助你搜索内容

使用 Python3 编写的 Web 漏洞扫描器

安全、模块化的 MCP 服务器,封装了 nmap、nuclei、gobuster、subfinder、httpx、nikto、sqlmap,用于 AI 驱动的渗透测试。

通过非破坏性 Nuclei 模板检测 GitLab CE/EE 中的 CVE-2026-19478,该模板通过 touch 触发 GraphQL 回退字段方法调用,并在不进行破坏性调用的情况下确认存在漏洞的实例。

用于检测 CVE-2024-40725 Apache HTTP Server 源代码泄露的扫描器;探测直接路径与子请求路径,对受影响版本进行指纹识别,并输出 JSON 报告供 CI/CD 使用。

CVE-2024-38856 漏洞利用程序,影响 Apache OFBiz 18.12.15 之前的版本

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Events Manager < 7.4.1 - 未经身份验证的权限提升至管理员

CVE-2026-64638 (XSS2Shell) 的非破坏性检测器 — WordPress 预认证 XSS 反射原语

CVE-2026-56292 - 用于 Joomla 的 AcyMailing 未认证 SQL 注入扫描器

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Nuclei 检测模板,用于 CVE-2026-41473,该漏洞是 CyberPanel AI Scanner 2.4.4 之前版本中未认证的读写 API 访问缺陷。使用两个 HTTP 探针确认缺少身份验证。