All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)
☆304Mar 12, 2024Updated last year
Alternatives and similar repositories for Dependency-Confusion
Users that are interested in Dependency-Confusion are comparing it to the libraries listed below
Sorting:
- i will upload more templates here to share with the comunity.☆567Apr 17, 2024Updated last year
- ☆756Jun 26, 2024Updated last year
- ☆861Dec 26, 2025Updated 2 months ago
- Asset inventory of over 800 public bug bounty programs.☆1,520Feb 14, 2025Updated last year
- Tool to check for dependency confusion vulnerabilities in multiple package management systems☆778Aug 19, 2024Updated last year
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆45Jun 3, 2024Updated last year
- Never forget where you inject.☆298Aug 15, 2025Updated 6 months ago
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!☆2,552Mar 3, 2026Updated last week
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzer☆382May 19, 2023Updated 2 years ago
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets☆1,530Updated this week
- A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues☆374Jul 25, 2023Updated 2 years ago
- DepFine Is a tool to find the unregistered dependency based on dependency confusion valunerablility and lead to RCE☆27Nov 28, 2021Updated 4 years ago
- A path-normalization pentesting tool.☆151Jan 22, 2026Updated last month
- ☆148Dec 23, 2022Updated 3 years ago
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist☆1,500Jan 8, 2026Updated 2 months ago
- Collection of Facebook Bug Bounty Writeups☆706Jan 16, 2026Updated last month
- Simple tool to gather domains from crt.sh using the organization name☆102Dec 16, 2021Updated 4 years ago
- JSNotify is a Python script designed to monitor JavaScript files in a specified directory for changes. This tool can be used by developer…☆18Nov 15, 2023Updated 2 years ago
- Authorization-Nuclei-Templates☆39Sep 16, 2024Updated last year
- My Priv8 Nuclei Templates☆339May 12, 2024Updated last year
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆89May 2, 2024Updated last year
- A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidde…☆434Oct 16, 2025Updated 4 months ago
- De-clutter a list of URLs☆385Feb 3, 2026Updated last month
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications☆1,293Aug 7, 2025Updated 7 months ago
- Real-world infosec wordlists, updated regularly☆1,642Mar 2, 2026Updated last week
- Find related domains of a given domain.☆104Aug 5, 2023Updated 2 years ago
- ☆251May 25, 2021Updated 4 years ago
- ☆809Jul 28, 2024Updated last year
- fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.☆936Aug 24, 2023Updated 2 years ago
- 1337 Wordlists for Bug Bounty Hunting☆931Updated this week
- Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests w…☆631Feb 22, 2026Updated 2 weeks ago
- A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomain…☆888May 3, 2023Updated 2 years ago
- A repository that includes all the important wordlists used while bug hunting.☆1,379Mar 11, 2023Updated 2 years ago
- Automated Tool for Testing Header Based Blind SQL Injection☆323Jul 23, 2023Updated 2 years ago
- Hidden parameters discovery suite☆2,028Sep 8, 2024Updated last year
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,089Aug 14, 2024Updated last year
- ☆99Mar 6, 2023Updated 3 years ago
- Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!☆1,313Updated this week
- ShoLister is a tool that collects all available subdomains for specific hostname or organization from Shodan. The tool is designed to be …☆60May 10, 2022Updated 3 years ago