A curated list of MCP servers for bug bounty.
☆65Oct 6, 2025Updated 9 months ago
Alternatives and similar repositories for awesome-bugbounty-mcp
Users that are interested in awesome-bugbounty-mcp are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 5 months ago
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 7 months ago
- Argus is used to test for Blind XSS and SSRF vulnerbilities or any sort of OOB detection☆14Nov 1, 2024Updated last year
- Convert your HackerOne reports into reusable AI skills.☆104Mar 9, 2026Updated 4 months ago
- Burpsuite Extension for Jsmon☆25Jul 1, 2026Updated 2 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A complete, beginner-friendly bug bounty roadmap that takes you from zero experience to earning your first bounty.☆1,410Sep 5, 2025Updated 10 months ago
- Morgan is a powerful tool designed to help security researchers, developers, and security auditors identify sensitive information, vulner…☆57Feb 2, 2025Updated last year
- ☆30Sep 9, 2025Updated 10 months ago
- Scans WordPress sites to find unclaimed plugin slugs on the public directory.☆27Oct 12, 2025Updated 9 months ago
- # 🕵️ PathCatcher v1.0 - Path Traversal & LFI Scanner☆24Jul 13, 2025Updated last year
- CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)☆15Apr 18, 2026Updated 3 months ago
- Documenting all the sources from where I'm learning Mobile(adnroid/IOS) bug bounty so if another researcher want to start with mobile bug…☆57May 23, 2026Updated last month
- ☆11Apr 8, 2024Updated 2 years ago
- Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast☆20Oct 5, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Vite Arbitrary File Read Exploit☆15Jun 25, 2025Updated last year
- ☆47Aug 12, 2025Updated 11 months ago
- ♥☆220Sep 7, 2025Updated 10 months ago
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- A collection of in-depth studies authored by me on JavaScript engine vulnerabilities.☆49Feb 6, 2026Updated 5 months ago
- A powerful Burp Suite extension that automatically detects JavaScript URLs from HTTP traffic, scans them using TruffleHog for secrets det…☆32Oct 23, 2025Updated 8 months ago
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 5 months ago
- Framework Automatizado de Reconocimiento y Explotación☆17Mar 8, 2026Updated 4 months ago
- API-Pentesting-Checklist☆28Feb 27, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- JSBerg is a fast and efficient URL scraper that extracts links, JavaScript files, CSS files, images, and inline URLs from a list of websi…☆24Mar 19, 2025Updated last year
- A powerful command-line interface for interacting with the [RapidDNS API](https://rapiddns.io/help/api). This tool allows you to perform …☆35Feb 22, 2026Updated 4 months ago
- ☆52Feb 20, 2026Updated 5 months ago
- This project is an Automated Penetration Testing and Vulnerability Scanning Framework. It is designed to all-in-one automated handles eve…☆21Jun 15, 2026Updated last month
- Free BugBounty KrazePlanetTraining☆58Dec 17, 2025Updated 7 months ago
- ☆56Jun 28, 2026Updated 3 weeks ago
- Acunetix automate telegram bot☆12Jul 19, 2024Updated 2 years ago
- Scan websites for exposed Supabase JWTs, enumerate accessible tables, and detect sensitive data exposure automatically.☆124Dec 29, 2025Updated 6 months ago
- SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the …☆16Nov 24, 2025Updated 7 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- IP Finder tool, ipfinder collects IP addresses from Shodan search queries.☆17Dec 12, 2025Updated 7 months ago
- This plugin is inspired by tools.slcyber.io. It contains two tools: Surf (an SSRF target discovery tool) and Wordlists (custom wordlists …☆23Jan 19, 2026Updated 6 months ago
- F5 BIG-IP unauthenticated remote code execution (RCE) and authentication bypass vulnerability!☆11Oct 30, 2023Updated 2 years ago
- ☆15Mar 21, 2025Updated last year
- Swagger UI >=3.14.1 < 3.38.0 XSS payload☆25Mar 31, 2024Updated 2 years ago
- ☆65Sep 8, 2025Updated 10 months ago
- A python script to automatically dump files and source code of a Symfony server in debug mode.☆13Feb 11, 2025Updated last year