ENNAENNA

Vulnerability Scanning

22 tools indexed

Vulnerability scanning and security auditing tools that detect CVEs, misconfigurations, outdated software, and security weaknesses across networks, web applications, containers, and code. Essential for both offensive assessments and defensive security posture management.

Nuclei

Go
Featured

Fast vulnerability scanner driven by YAML templates. Thousands of community-contributed detection templates.

template-basedcvemisconfigprojectdiscovery
28.1k3.4k24d ago

sqlmap

Python

Automatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws.

sql-injectiondatabaseautomatedclassic
37.2k6.2k27d ago

WPScan

Ruby

WordPress security scanner. Enumerates plugins, themes, users, and checks for known vulnerabilities.

wordpressplugin-enumcvecms
9.6k1.3k27d ago

OpenVAS

C
Featured

Full-featured vulnerability scanner. 50,000+ NVTs, credentialed scanning, compliance checks.

enterprisenvtcompliancecredentialed
4.6k76924d ago

XSStrike

Python

Advanced XSS detection suite. Fuzzing engine, context analysis, and WAF detection/bypass capabilities.

xsswaf-bypassfuzzingcontext-analysis
14.9k2.1k1y ago

Commix

Python

Automated OS command injection exploitation tool. Tests web apps for command injection vulnerabilities.

command-injectionautomatedweb-app
5.7k92829d ago

testssl.sh

Shell

Command-line tool for checking TLS/SSL ciphers, protocols, and cryptographic flaws on any port.

tlssslcipher-checkheartbleed
9.0k1.1k26d ago

Trivy

Go

Comprehensive vulnerability scanner for containers, filesystems, git repos, and Kubernetes with SBOM generation.

container-securitysbomvulnerability-scanneriac-scanning
34.7k32627d ago

Grype

Go

Vulnerability scanner for container images and filesystems that matches installed packages against known CVEs.

container-securitycve-scanningsbomimage-scanning
12.1k79227d ago

Semgrep

OCaml

Lightweight static analysis engine for finding bugs and enforcing code standards across 30+ languages with custom rules.

saststatic-analysiscode-scanningcustom-rules
14.9k92324d ago

DalFox

Go

Parameter analysis and XSS scanner with automatic payload generation, DOM-based detection, and pipeline support.

xssparameter-analysisdom-xssreflected-xss
4.9k52026d ago

Retire.js

JavaScript

Scanner for detecting use of JavaScript libraries with known vulnerabilities in web applications.

javascriptdependency-scanningcveweb-security
4.1k43727d ago

OSV-Scanner

Go

Google's dependency vulnerability scanner using the OSV.dev database across multiple language ecosystems.

dependency-scanningscasupply-chaincve
9.9k66424d ago

Lynis

Shell

Security auditing and hardening tool for Linux/macOS with compliance testing for HIPAA, ISO27001, and PCI DSS.

hardeningauditcompliancecis-benchmark
15.6k1.6k3mo ago

afrog

Go

Fast vulnerability scanner with custom PoC support for CVEs, default credentials, and command injection.

vuln-scannerpoccvefast
4.2k4681mo ago

Vuls

Go

Agentless vulnerability scanner for Linux and FreeBSD with CVE detection.

vulnerabilityscanneragentlesscve
12.1k1.2k24d ago

Infection Monkey

Python

Automated adversary emulation platform for validating network security controls.

breach-simulationadversarytesting
7.0k8181y ago

boofuzz

Python

Network protocol fuzzing framework and successor to the Sulley fuzzer.

fuzzingprotocolnetwork
2.3k3801mo ago

garak

Python

NVIDIA's LLM vulnerability scanner. Tests language models for prompt injection, jailbreaks, data leakage, and harmful outputs.

llm-securityai-red-teamprompt-injectionjailbreak
7.7k90324d ago

Osmedeus

Go

Automated reconnaissance and vulnerability scanning workflow engine. Chains recon, scanning, and exploitation into configurable pipelines.

automationrecon-pipelineworkflow-enginevulnerability-scanning
6.2k9791mo ago

DeepAudit

Python

Multi-agent AI code auditing system with automated sandbox PoC verification. Has discovered 49 CVEs across 17 open-source projects.

ai-auditcode-reviewcve-discoverymulti-agent
5.9k52020d ago

Titus

Go

High-performance secrets scanner by Praetorian with CLI, Go library, Burp extension, and Chrome extension. 487 detection rules.

secrets-detectionhigh-performanceburp-extensionapi-keys
5394529d ago