Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , CVE-2024-38473 , CVE-2023-38709
☆123Oct 5, 2024Updated last year
Alternatives and similar repositories for apache-vulnerability-testing
Users that are interested in apache-vulnerability-testing are comparing it to the libraries listed below
Sorting:
- ☆16Mar 29, 2024Updated last year
- Passively check for XSS character encodings☆18Updated this week
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆28Jul 21, 2024Updated last year
- Find The Admin Panel & SQL Injection Endpoints, Using Google Dorks !!!☆24Nov 15, 2024Updated last year
- ☆41Mar 12, 2025Updated 11 months ago
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers☆311Mar 31, 2024Updated last year
- POC for CVE-2024-40348. Will attempt to read /etc/passwd from target☆32Jul 21, 2024Updated last year
- SNMP Bash Script to discover valid community strings, dump basic information, check for write permission and check for RCE.☆11Apr 27, 2024Updated last year
- This tools used for Automating finding of subdomain, and checking for alive subdomain, and gathering js files from all the subdomain and …☆22Jun 28, 2024Updated last year
- POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.☆126Jul 12, 2024Updated last year
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆24Feb 20, 2024Updated 2 years ago
- Find subdomains on GitLab.☆106Apr 28, 2024Updated last year
- A collaborative hub for Nuclei templates. Contribute, share, and explore powerful vulnerability detection tools!☆50Feb 1, 2025Updated last year
- ☆35Aug 2, 2022Updated 3 years ago
- The Most Advanced Client-Side Prototype Pollution Scanner☆246Feb 3, 2026Updated last month
- Your perfect recognition for HTMLi and XSS☆19Oct 14, 2024Updated last year
- CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection☆17Jan 12, 2025Updated last year
- An automated bug hunting tool for comprehensive reconnaissance, including subdomain enumeration, port scanning, vulnerability detection, …☆13Jun 24, 2025Updated 8 months ago
- Unauthorized Access to Metadata and User Data like CTF☆28Nov 30, 2024Updated last year
- ☆33Apr 22, 2025Updated 10 months ago
- Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled☆48Dec 23, 2024Updated last year
- ☆184Oct 22, 2024Updated last year
- All-in Fuzzer. Burp suite extension for auto fuzzing params, headers, body☆36Dec 13, 2025Updated 2 months ago
- ☆47May 31, 2024Updated last year
- SubOwner - A Simple tool check for subdomain takeovers.☆116Oct 18, 2024Updated last year
- [CVE-2024-4956] Nexus Repository Manager 3 Unauthenticated Path Traversal Bulk Scanner☆17Sep 26, 2024Updated last year
- Dnsbruter is a powerful tool designed to perform active subdomain enumeration and discovery. It uses DNS resolution to efficiently brutef…☆125Dec 17, 2024Updated last year
- Determine the running software version of a remote F5 BIG-IP management interface.☆69Jan 3, 2024Updated 2 years ago
- POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.☆31Jun 29, 2024Updated last year
- ☆11Sep 15, 2024Updated last year
- CosmicSting (CVE-2024-34102)☆48Sep 5, 2024Updated last year
- Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers P…☆33Jul 13, 2025Updated 7 months ago
- Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)☆78Jun 6, 2024Updated last year
- RCE through a race condition in Apache Tomcat☆56Dec 21, 2024Updated last year
- Community curated list of templates for the nuclei engine to find security vulnerabilities.☆81Nov 24, 2025Updated 3 months ago
- Every Nuclei template that has ever appeared on Github☆36Jun 2, 2022Updated 3 years ago
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.☆43Dec 4, 2025Updated 3 months ago
- i will upload more templates here to share with the comunity.☆567Apr 17, 2024Updated last year
- Exploiting XXE Vulnerabilities on Microsoft SharePoint Server and Cloud via Confused URL Parsing☆32Jun 6, 2024Updated last year