vavkamil / XSSwagger
A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks
☆58Updated 5 years ago
Alternatives and similar repositories for XSSwagger:
Users that are interested in XSSwagger are comparing it to the libraries listed below
- ☆59Updated 9 months ago
- Burp Bounty profiles☆82Updated 3 years ago
- ☆44Updated 3 years ago
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 3 years ago
- Script to test open Akamai ARL vulnerability.☆71Updated 3 years ago
- A Payload Injector for bugbounties written in go☆70Updated 4 years ago
- ☆60Updated 4 years ago
- Get the scope of your bugcrowd programs☆67Updated 4 years ago
- Misc bounty and vulndisc things☆84Updated 4 years ago
- ☆38Updated 4 years ago
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆64Updated 5 years ago
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Updated 4 years ago
- Expand urls into one url for each path depth☆34Updated 4 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 4 years ago
- ☆95Updated 3 years ago
- MNS is a security and reconnaissance tool for monitoring new subdomains☆69Updated this week
- Wraps projectdiscovery's cdncheck library to exclude CDN hosts from input passed over stdin☆43Updated 2 years ago
- My Tools For Bug Bounty☆66Updated 7 months ago
- Horizontal Domain Discovery☆76Updated last year
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.☆108Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆35Updated 4 years ago
- Extract SSL certificate data (Subject Name, Subject Alt Names, Organisation)☆42Updated 2 months ago
- Simple tool to test for SSRF/OOB HTTP Read within the Path of a request☆30Updated 5 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- Recon Custom WordList Ganerator☆58Updated 4 years ago
- Some of my bug bounty tools☆50Updated 5 years ago
- jenkinz is a tool to retrieve every build for every job ever created and run on a given Jenkins instance.☆67Updated 5 years ago