Web Application Tools

462 tools
Commix
Commix
Open Source Kali Web Application

Automated all-in-one OS command injection and exploitation tool. Detects and exploits command injection vulnerabilities in web applications …

Content-Bruteforcing-Wordlist
Content-Bruteforcing-Wordlist
Free Password Attacks Web Application

Wordlist for content(directory) bruteforce discovering with Burp or dirsearch

Cookie-Grabber-Creator
Cookie-Grabber-Creator
Free Web Application

[V5] This will help you setup a grabber with the following features: History, Passwords, Tokens, Cookies, Emails, IP Adresses, Roblox Login …

core
core
Open Source Web Application

Open source compliance automation for SOC 2, GDPR, ISO27001, NIST 800-53, and more

cors
cors
Open Source Web Application

perhaps the best CORS middleware library for Go

Corsy
Corsy
Open Source Web Application

Lightweight program to find all known misconfigurations in CORS (Cross-Origin Resource Sharing) implementations. Tests for null origin, pre-…

crt.sh
crt.sh
Free Reconnaissance Web Application

Crtsh Subdomain Enumeration | This bash script makes it easy to quickly save and parse the output from https://crt.sh website.

csp-builder
csp-builder
Open Source Web Application

Build Content-Security-Policy headers from a JSON file (or build them programmatically)

csprecon
csprecon
Open Source Reconnaissance Web Application

Discover new target domains using Content Security Policy

ctf-super-hub
ctf-super-hub
Free Forensics Reconnaissance

面向小白用户的 CTF / 逆向 Skills 整合包:自动分流、头脑风暴、教学模式、比赛模式、只提示模式

cut-cdn
cut-cdn
Open Source Reconnaissance Web Application

✂️ Removing CDN IPs from the list of IP addresses

CVE-2022-23808
CVE-2022-23808
Free Exploitation Web Application

A series of weaknesses has been discovered that could allow an attacker to inject malicious code in to aspects of the setup script, which ca…

CVE-2023-27372
CVE-2023-27372
Free Exploitation Web Application

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions ar…

CVE-2024-4040-SSTI-LFI-PoC
CVE-2024-4040-SSTI-LFI-PoC
Free Exploitation Web Application

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

CVE-Master
CVE-Master
Open Source Exploitation Web Application

收集本人自接触渗透测试用于漏洞验证的所有热门CVE、POC、CNVD攻击有效载荷+测试工具+FUZZ,一个仓库满足许多攻击测试场景,开箱即用.

cvemapping
cvemapping
Free Exploitation Reconnaissance

This repo Gathers all available cve exploits from github.⚠️ Be careful Malware.

cwe-tool
cwe-tool
Open Source Exploitation Web Application

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

cyber-neo
cyber-neo
Open Source Scanning & Enumeration Web Application

Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP 2025 Top 10 and CWE Top 25 cat…

CyberSecurity_Conferences
CyberSecurity_Conferences
Open Source Forensics Reconnaissance

List of some cybersecurity conferences

Cybersecurity-Notes
Cybersecurity-Notes
Open Source Forensics Post-Exploitation

Cybersecurity Notes For Intermediate and Advanced Hackers | CEH Exam Prep Also Included

CyberStrike
CyberStrike
Open Source Exploitation Web Application

AI-powered offensive security agent with 7,300+ actionable security skills. Autonomous pentesting powered by MITRE ATT&CK (2,000+ Atomic tes…

daily-bugbounty-writeups
daily-bugbounty-writeups
Free Web Application

This repository contains Bug Bounty writeups

Dalfox
Dalfox
Open Source Web Application

Fast parameter analysis and XSS scanner. Features DOM-based XSS detection, built-in BAC (Blind XSS), custom payloads, headless Chrome suppor…

dalfox
dalfox
Open Source Exploitation Web Application

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.