vulnerability-scanning

93 tools and resources

NEW

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

AWVS Logo

AWVS

0 (0)

A hosted web application security testing tool that enables security researchers to register, activate their accounts, and scan web applications for vulnerabilities.

Sn1per Logo

Sn1per

0 (0)

An open-source attack surface management platform for identifying and managing vulnerabilities

A multi-threaded scanner for identifying CORS flaws and misconfigurations

A tool for finding and exploiting SQL injection vulnerabilities in web applications

WPRecon Logo

WPRecon

0 (0)

WPRecon is a tool for recognizing vulnerabilities and blackbox information for WordPress.

XSpear Logo

XSpear

0 (0)

A powerful XSS scanning and parameter analysis tool

SSRFire Logo

SSRFire

0 (0)

Automated SSRF finder with options for XSS and open redirects

surf Logo

surf

0 (0)

A tool to escalate SSRF vulnerabilities on modern cloud environments

A simple Swagger-ui scanner that detects old versions vulnerable to various XSS attacks

SubOver Logo

SubOver

0 (0)

A powerful tool for finding and exploiting subdomain takeover vulnerabilities

A directory traversal fuzzer for finding and exploiting directory traversal vulnerabilities.

A smart SSRF scanner using different methods like parameter brute forcing in post and get requests.

A Burp intruder extender for automating and validating XSS vulnerabilities

A command-line tool for identifying NoSQL injection vulnerabilities in MongoDB databases

A better version of my xssfinder tool that scans for different types of XSS on a list of URLs.

A tool for testing subdomain takeover possibilities at a mass scale.

A simple SSRF-testing sheriff written in Go

A Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

Burp extension for identifying cloud buckets and testing for vulnerabilities

A free online tool to scan for DOM-based XSS vulnerabilities in HTML, JavaScript, and CSS files.

A portable version of XSSHunter.com for finding and exploiting Cross-Site Scripting (XSS) vulnerabilities.

AuditJS Logo

AuditJS

0 (0)

Audits JavaScript projects for known vulnerabilities and outdated package versions using OSS Index v3 REST API.

An extensible, heuristic-based vulnerability scanning tool for installed npm packages.

A simple, fast web crawler for discovering endpoints and assets in a web application

Dynamic application security testing tool for identifying and fixing web application vulnerabilities.

A tool for scanning websites with open .git repositories and dumping their content for Bug Hunting/Pentesting Purposes.

A demonstration site for the Acunetix Web Vulnerability Scanner, intentionally vulnerable to various web-based attacks.

Static application security testing (SAST) tool for scanning source code against security and privacy risks.

Rexsser Logo

Rexsser

0 (0)

A Burp plugin for identifying potential vulnerabilities in web applications

A runtime threat management and attack path enumeration tool for cloud-native environments

Flan Logo

Flan

0 (0)

A vulnerability scanner that helps you identify and fix vulnerabilities in your code

FullHunt is a next-generation attack surface security platform that enables companies to discover, monitor, and secure their external attack surfaces.

Check for known vulnerabilities in your Node.js installation.

altdns Logo

altdns

0 (0)

A tool for generating permutations, alterations and mutations of subdomains and resolving them

A tool for privilege escalation within Linux environments by targeting vulnerabilities in SUDO usage.

Patch-level verification tool for bundler to check for vulnerable gems and insecure sources.

A tool for exploiting SSRF and gaining RCE in various servers

A series of small test cases designed to exercise different parts of a static security analyzer

A series of vulnerable virtual machine images with documentation to teach Linux, Apache, PHP, MySQL security.

npq Logo

npq

0 (0)

A tool that safely installs packages with npm/yarn by auditing them as part of your install process.

A tool that showcases the attack surface of a given Android device, highlighting potential vulnerabilities and security risks.

WPScan Logo

WPScan

0 (0)

WordPress security scanner for identifying vulnerabilities in WordPress websites.

Next-generation Linux exploit suggester with improved features for finding privilege escalation vulnerabilities.

Android vulnerability analysis system with efficient scanning and high accuracy.

Pagodo Logo

Pagodo

0 (0)

Automate Google Hacking Database scraping and searching with Pagodo, a tool for finding vulnerabilities and sensitive information.

A comprehensive guide to Nessus, a vulnerability scanner, covering data directories, binary directories, logs directories, plugin directories, advanced settings, API, and good practices.

AEM (Adobe Experience Manager) Hacker is a tool designed to help security researchers and penetration testers identify and exploit vulnerabilities in AEM-based systems.

Finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.

Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.

A web security tool that scans for vulnerabilities and known attacks.

Compares target's patch levels against Microsoft vulnerability database and detects missing patches.

A demonstration site for the Acunetix Web Vulnerability Scanner, featuring intentionally vulnerable PHP code to test web application security.

A Docker analysis tool for identifying potential security vulnerabilities and weaknesses in Docker environments

XSSer Logo

XSSer

0 (0)

Automatic tool for pentesting XSS attacks against different applications

Powerful PowerShell script for identifying missing software patches for local privilege escalation vulnerabilities.

A powerful penetration testing platform for identifying vulnerabilities and weaknesses in computer systems.

w3af Logo

w3af

0 (0)

Open source web application security scanner with 200+ vulnerability identification capabilities.

MetaHub Logo

MetaHub

0 (0)

Automated contextual security findings enrichment and impact evaluation tool for vulnerability management.

A centralized platform for managing open source components and automating software supply chain security.

CVE Ape Logo

CVE Ape

0 (0)

A tool to find and search for registered CVEs, creating a local CVE database for offline use.

Nessus efficiently scans for system vulnerabilities, misconfigurations, and compliance issues.

Amass Logo

Amass

0 (0)

Amass by OWASP performs comprehensive attack surface mapping and asset discovery.

A free online tool that scans and fixes common security issues in WordPress websites.

Commix Logo

Commix

0 (0)

Open source penetration testing tool for detecting and exploiting command injection vulnerabilities.

Clair Logo

Clair

0 (0)

An open source project for static analysis of vulnerabilities in application containers

Simple script to check a domain's email protections and identify vulnerabilities.

drozer Logo

drozer

0 (0)

A security testing framework for Android with tools to search for vulnerabilities and interact with the Android Runtime.

Dagda Logo

Dagda

0 (0)

A tool for static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers

Wapiti Logo

Wapiti

0 (0)

Web-application vulnerability scanner with extensive coverage of security testing modules.

Vuls Logo

Vuls

0 (0)

Vulnerability scanner for Linux/FreeBSD, written in Go, agent-less, informs users of vulnerabilities related to the system and affected servers.

Gamma Ray is a software that helps developers to look for vulnerabilities on their Node.js applications with a pluggable infrastructure for integration with vulnerabilities databases.

Automate version scraping and vulnerability scanning for Ruby on Rails stacks.

Cloud-based service for testing and analyzing Android and iOS apps for malware, vulnerabilities, and security threats.

Pompem Logo

Pompem

0 (0)

Automate the search for Exploits and Vulnerabilities in important databases.

Arachni

0 (0)

An open-source web application security scanner framework that identifies vulnerabilities in web applications.

An Open Source supply chain security and auditing tool that tracks projects and dependencies, monitoring for vulnerabilities and issues.