GitHub repo leaderboard by stars, growth rate and activity.
Automatic SQL injection and database takeover tool
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
Web Application Security Scanner Framework
Automated NoSQL database enumeration and web application exploitation tool.
jSQL Injection is a Java application for automatic SQL database injection.
massive SQL injection vulnerability scanner
Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
[VscanPlus内外网漏洞扫描工具]已更新HW热门漏洞检测POC。基于veo师傅的漏扫工具vscan二次开发的版本,端口扫描、指纹检测、目录fuzz、漏洞扫描功能工具,批量快速检测网站安全隐患。An open-source, cross-platform website vulnerability scanning tool that helps you quickly detect website security vulnerabilities.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | Automatic SQL injection and database takeover tool | Python | 38,395 | last pushed 2 days ago | |
| 2 | SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits. | Go | 22,549 | last pushed 1 week ago | |
| 3 | Damn Vulnerable Web Application (DVWA) | PHP | 13,635 | last pushed 3 days ago | |
| 4 | Web Application Security Scanner Framework | Ruby | 4,042 | last pushed 5 months ago | |
| 5 | Automated NoSQL database enumeration and web application exploitation tool. | Python | 3,349 | last pushed 1 month ago | |
| 6 | jSQL Injection is a Java application for automatic SQL database injection. | Java | 1,780 | last pushed 5 weeks ago | |
| 7 | massive SQL injection vulnerability scanner | Python | 1,231 | last pushed 8 years ago | |
| 8 | Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone. | Go | 712 | last pushed 4 days ago | |
| 9 | 一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能 | Python | 644 | last pushed 7 years ago | |
| 10 | [VscanPlus内外网漏洞扫描工具]已更新HW热门漏洞检测POC。基于veo师傅的漏扫工具vscan二次开发的版本,端口扫描、指纹检测、目录fuzz、漏洞扫描功能工具,批量快速检测网站安全隐患。An open-source, cross-platform website vulnerability scanning tool that helps you quickly detect website security vulnerabilities. | Go | 352 | last pushed 6 months ago |
All · 11,474