Vulnerability Management for Fuzzing

Vulnerability management tools for security scanning, penetration testing, bug bounty programs, and vulnerability assessment. Task: Fuzzing

Browse 22 security tools

Automated fuzz & penetration testing tool for automotive ECUs and software.

Automated IoT device security assessment tool with fuzzing & vuln testing.

Offensive security platform for attack surface discovery and risk management

An AI-powered wrapper for ffuf that automatically suggests relevant file extensions for web fuzzing based on target URL analysis and response headers.

SecLists is a comprehensive repository of security testing lists including usernames, passwords, URLs, fuzzing payloads, and web shells used during penetration testing and security assessments.

BlackWidow is a Python-based web application scanner that combines OSINT gathering with automated fuzzing to identify OWASP vulnerabilities in target websites.

A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.

Automatic SSRF fuzzer and exploitation tool

A collection of Local File Inclusion (LFI) vulnerability tests and exploitation techniques designed for use with Burp Suite.

A Python-based tool that automates the identification and exploitation of file inclusion and directory traversal vulnerabilities in web applications.

A directory traversal fuzzer for finding and exploiting directory traversal vulnerabilities.

A CRLF and open redirect fuzzer

A cross-platform web fuzzer written in Nim

qsfuzz is a rule-based fuzzing tool for testing query string parameters in web applications to identify security vulnerabilities.

A collection of payloads and methodologies for web pentesting.

Fast web fuzzer written in Go

ParamPamPam is an open-source tool that detects and exploits web application vulnerabilities using fuzzing, SQL injection, and XSS techniques.

A fast and flexible web fuzzer for identifying vulnerabilities in web applications

A WebSocket Manipulation Proxy with a user interface to capture, intercept, and send custom messages for WebSocket and Socket.IO communications.

Boofuzz is a network protocol fuzzing tool that aims to fuzz everything

FuzzDB is an open-source dictionary of attack patterns and predictable resource locations for dynamic application security testing and vulnerability discovery.

An image with commonly used tools for creating a pentest environment easily and quickly, with detailed instructions for launching in a VPS.