LFI-FINDER is an open-source tool available on GitHub that focuses on detecting Local File Inclusion (LFI) vulnerabilities
☆303Jan 7, 2024Updated 2 years ago
Alternatives and similar repositories for LFI-FINDER
Users that are interested in LFI-FINDER are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple tool for bypassing file upload restrictions.☆908Jul 22, 2024Updated 2 years ago
- A command-line utility designed to recursively spider webpages for URLs. It works by actively traversing websites - following links embed…☆111Dec 8, 2025Updated 8 months ago
- NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Re…☆1,864Apr 17, 2026Updated 4 months ago
- Automated Tool for Testing Header Based Blind SQL Injection☆331Jul 23, 2023Updated 3 years ago
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers☆311Mar 31, 2024Updated 2 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- An XSS exploitation command-line interface and payload generator.☆1,440Jan 19, 2025Updated last year
- Nodesub is a command-line tool for finding subdomains in bug bounty programs☆149Aug 1, 2024Updated 2 years ago
- Lfi Scan Tool☆112May 2, 2026Updated 4 months ago
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzer☆388May 19, 2023Updated 3 years ago
- DNSleuth sniffs DNS packets, i.e, allowing you to spy on the DNS queries your machine is making☆104Aug 9, 2023Updated 3 years ago
- With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the netw…☆147May 31, 2024Updated 2 years ago
- Subprober is a powerful and efficient subdomain scanning tool written in Python. With the ability to handle large lists of subdomains. Th…☆268May 17, 2026Updated 3 months ago
- A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanning☆525Jul 5, 2023Updated 3 years ago
- Welcome to the Bug Hunter's Wordlists repository! 🐛🔍 This repository serves as a comprehensive collection of essential wordlists utiliz…☆156May 17, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A modern tool written in Python that automates your xss findings.☆481Nov 26, 2023Updated 2 years ago
- 「🔑」A tool used to hunt down API key leaks in JS files and pages☆939Mar 12, 2026Updated 5 months ago
- Burp Suite's extension to scan and crawl Single Page Applications☆106Apr 14, 2023Updated 3 years ago
- i will upload more templates here to share with the comunity.☆572Apr 17, 2024Updated 2 years ago
- ProxyChecker Made in NodeJS☆38Mar 15, 2022Updated 4 years ago
- Checks for SSRF using built-in custom Payloads after fetching URLs from Multiple Passive Sources & applying complex patterns aimed at SSR…☆134Jul 23, 2026Updated last month
- A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers☆360Dec 14, 2023Updated 2 years ago
- Exploit Proof-of-Concept code for XAMPP v3.3.0 — '.ini' Buffer Overflow (Unicode + SEH)☆13Nov 1, 2023Updated 2 years ago
- The most powerful CRLF injection (HTTP Response Splitting) scanner.☆598Oct 17, 2023Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- My Priv8 Nuclei Templates☆347May 12, 2024Updated 2 years ago
- Passively check for XSS character encodings☆20Mar 9, 2026Updated 5 months ago
- This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the …☆73May 21, 2023Updated 3 years ago
- An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer☆753May 19, 2023Updated 3 years ago
- BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for c…☆446Dec 30, 2025Updated 8 months ago
- Dump Windows SAM hashes☆43Aug 9, 2023Updated 3 years ago
- This Repositories contains list of One Liners with Descriptions and Installation requirements☆508Jun 28, 2025Updated last year
- PowerSploit - A PowerShell Post-Exploitation Framework☆22Jun 11, 2022Updated 4 years ago
- A collection of one-liners for bug bounty hunting.☆1,630Jan 21, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Small toolkit for extracting information and dumping sensitive strings from Windows processes☆116Jul 17, 2024Updated 2 years ago
- it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web pag…☆120Jul 18, 2023Updated 3 years ago
- AllForOne allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories,☆739Mar 21, 2024Updated 2 years ago
- Dump place details from Google Maps like phone,email,website,and reviews☆73Jun 3, 2025Updated last year
- Template Nuclei SSTI☆34Nov 18, 2025Updated 9 months ago
- Local file inclusion exploitation tool☆983May 19, 2026Updated 3 months ago
- APK Infrastructure Investigator☆66Jun 20, 2023Updated 3 years ago