NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration techniques
-
Updated
Aug 20, 2025 - Shell
NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration techniques
A fast tool to fetch URLs from HTML attributes by crawl-in.
SQLMutant is a powerful SQL injection testing tool that includes both passive and active reconnaissance processes for any given domain. It filters URLs to identify those with parameters susceptible to SQL injection formats and then performs injection attacks. These attacks include pattern matching, error analysis, and timing attacks.
Collect XSS vulnerable parameters from entire domain.
Tool to automate recon
Cross Injector — A Python Script for Cross-Site Scripting (XSS) Detection
(CLI wrapper) Takes a list of URLs and retrieve screenshots of older versions stored on the Wayback Machine.
Automated way to extract juicy info with subfinder and waybackurls
JIRA"YA is a vulnerability analyzer for JIRA instances. It runs active scans to identify vulnerabilities by interacting with the host and conducting tests.
CoupDeWeb is an automated web vulnerability scanner designed for security researchers and developers. It scans for potential vulnerable endpoints, targeting various types of vulnerabilities such as XSS, SQL Injection, and more.
GhostHunter is a powerful and user-friendly tool designed to uncover hidden treasures from the Wayback Machine. It allows you to search for archived URLs (snapshots) of a specific domain, filter them by file extensions, and save the results in an organized manner.
Bring all the URLs that the Wayback machine knows for one or more domain names.
This Script contains tools like assetfinder, amass, httprobe, subjack, nmap, waybackurls and gowitness
Fetch all the URLs that the Wayback Machine knows about for a domain
LazyXSS is a tool that can help you scan for reflected XSS, LFI without any effort.
Wordlist Generator from Live Website + Wayback URLs
URL Extractor | Designed By YogSec is a powerful Bash script that helps you extract URLs from a single file or all files inside a folder
Generate concise and targeted wordlists from Wayback Machine URLs
waybacksteroids — Fast multi-domain Wayback Machine endpoint enumerator.
Add a description, image, and links to the waybackurls topic page so that developers can more easily learn about it.
To associate your repository with the waybackurls topic, visit your repo's landing page and select "manage topics."