🎯 Fast CORS misconfiguration vulnerabilities scanner
☆1,146Nov 25, 2021Updated 4 years ago
Alternatives and similar repositories for CORScanner
Users that are interested in CORScanner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automatic SSRF fuzzer and exploitation tool☆3,533Sep 4, 2025Updated 7 months ago
- JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.☆2,925Nov 24, 2021Updated 4 years ago
- Burp suite 分块传输辅助插件☆2,033Feb 23, 2022Updated 4 years ago
- CORS Misconfiguration Scanner☆1,515Sep 17, 2022Updated 3 years ago
- Redis 4.x/5.x RCE☆978Nov 30, 2021Updated 4 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- A python script that finds endpoints in JavaScript files☆4,334Apr 13, 2024Updated 2 years ago
- SRC子域名资产监控☆1,298Jan 14, 2021Updated 5 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,489Oct 12, 2024Updated last year
- A powerful browser crawler for web vulnerability scanners☆3,031Mar 11, 2025Updated last year
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,799Apr 26, 2024Updated 2 years ago
- Burp被动扫描流量转发插件☆1,461Jun 17, 2024Updated last year
- TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.☆319May 22, 2023Updated 2 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,346Apr 18, 2023Updated 3 years ago
- 增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持☆965Jun 16, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- OneForAll是一款功能强大的子域 收集工具☆9,747Sep 12, 2025Updated 7 months ago
- 360/0Kee-Team/crawlergo动态爬虫结合长亭XRAY扫描器的被动扫描功能☆1,185Nov 10, 2021Updated 4 years ago
- A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅☆1,922Apr 3, 2026Updated 3 weeks ago
- python安全和代码审计相关资料收集 resource collection of python security and code review☆1,354Aug 6, 2020Updated 5 years ago
- 一个用于前端加密Fuzz的Burp Suite插件☆1,066Mar 6, 2020Updated 6 years ago
- A Swagger API Exploit☆1,373Jun 7, 2024Updated last year
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,148Apr 21, 2024Updated 2 years ago
- weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-201…☆2,071Nov 24, 2023Updated 2 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,394Dec 16, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed b…☆1,030Feb 5, 2021Updated 5 years ago
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,739Dec 1, 2024Updated last year
- Passive Security Scanner (被动式安全扫描器)☆1,948Feb 8, 2023Updated 3 years ago
- Enumeration sub domains(枚举子域名)☆1,069Dec 1, 2021Updated 4 years ago
- HTTP parameter discovery suite.☆6,209Feb 20, 2025Updated last year
- 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo☆817Nov 28, 2022Updated 3 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,020May 21, 2024Updated last year
- A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers☆2,367Dec 31, 2024Updated last year
- Python2编写的struts2漏洞全版本检测和利用工具☆1,414May 7, 2019Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Weblogic一键漏洞检测工具,V1.5,更新时间:20200730☆2,268May 22, 2023Updated 2 years ago
- This tool can be used to brute discover GET and POST parameters☆1,395Aug 24, 2019Updated 6 years ago
- 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。☆865Jul 21, 2019Updated 6 years ago
- 从wooyun中提取的payload,以及burp插件☆839Jun 17, 2022Updated 3 years ago
- mysql注入,bypass的一些心得☆1,327Jun 25, 2024Updated last year
- Shiro550/Shiro721 一键化利用工具,支持多种回显方式☆1,957Jun 4, 2021Updated 4 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,864Dec 4, 2025Updated 4 months ago