EN
ENNA

Vulnerability Scanning

12 tools indexed

Vulnerability scanning and security auditing tools that detect CVEs, misconfigurations, outdated software, and security weaknesses across networks, web applications, containers, and code. Essential for both offensive assessments and defensive security posture management.

Nuclei

Go
Featured

Fast vulnerability scanner driven by YAML templates. Thousands of community-contributed detection templates.

template-basedcvemisconfigprojectdiscovery
27.8k3.3k3d ago

sqlmap

Python

Automatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws.

sql-injectiondatabaseautomatedclassic
37.0k6.2k7d ago

WPScan

Ruby

WordPress security scanner. Enumerates plugins, themes, users, and checks for known vulnerabilities.

wordpressplugin-enumcvecms
9.5k1.3k1mo ago

OpenVAS

C
Featured

Full-featured vulnerability scanner. 50,000+ NVTs, credentialed scanning, compliance checks.

enterprisenvtcompliancecredentialed
4.5k7653d ago

XSStrike

Python

Advanced XSS detection suite. Fuzzing engine, context analysis, and WAF detection/bypass capabilities.

xsswaf-bypassfuzzingcontext-analysis
14.9k2.1k11mo ago

Commix

Python

Automated OS command injection exploitation tool. Tests web apps for command injection vulnerabilities.

command-injectionautomatedweb-app
5.7k9282d ago

testssl.sh

Shell

Command-line tool for checking TLS/SSL ciphers, protocols, and cryptographic flaws on any port.

tlssslcipher-checkheartbleed
9.0k1.1k12d ago

Trivy

Go

Comprehensive vulnerability scanner for containers, filesystems, git repos, and Kubernetes with SBOM generation.

container-securitysbomvulnerability-scanneriac-scanning
34.4k2363d ago

Grype

Go

Vulnerability scanner for container images and filesystems that matches installed packages against known CVEs.

container-securitycve-scanningsbomimage-scanning
11.9k7742d ago

Semgrep

OCaml

Lightweight static analysis engine for finding bugs and enforcing code standards across 30+ languages with custom rules.

saststatic-analysiscode-scanningcustom-rules
14.7k9052d ago

DalFox

Go

Parameter analysis and XSS scanner with automatic payload generation, DOM-based detection, and pipeline support.

xssparameter-analysisdom-xssreflected-xss
4.9k5171d ago

Retire.js

JavaScript

Scanner for detecting use of JavaScript libraries with known vulnerabilities in web applications.

javascriptdependency-scanningcveweb-security
4.1k4352d ago