Web Vulnerability Testing
Web Vulnerability Testing is a reference category for Red Team work. Select an upstream project only after confirming scope, authorization, license, and maintenance status.
8 published reference entries · reviewed catalogue metadata is shown on every card.
The world’s most widely used web app scanner. Free and open source active vulnerability scanner.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An open-source web server scanner which performs comprehensive tests against web servers for multiple items.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An open source Python tool designed to audit for as well as automate injection attacks and exploit default configuration weaknesses in NoSQL databases.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Automatic SQL injection and database takeover tool.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An advanced Cross-Site Scripting (XSS) scanner with intelligent payload generation and context analysis.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An automated tool for testing web applications for OS command injection vulnerabilities.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An integrated platform for performing security testing of web applications.
- Provenance
- community software
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A free command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as some cryptographic flaws.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.