awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to codingo/nosqlmap

Open-source alternatives to NoSQLMap

30 open-source projects similar to codingo/nosqlmap, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best NoSQLMap alternative.

  • sqlmapproject/sqlmapAvatar de sqlmapproject

    sqlmapproject/sqlmap

    37,676Voir sur GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    Pythondatabasedetectionexploitation
    Voir sur GitHub↗37,676
  • epinna/tplmapAvatar de epinna

    epinna/tplmap

    4,169Voir sur GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    Voir sur GitHub↗4,169
  • commixproject/commixAvatar de commixproject

    commixproject/commix

    5,757Voir sur GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Python
    Voir sur GitHub↗5,757

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Find more with AI search
  • wpscanteam/wpscanAvatar de wpscanteam

    wpscanteam/wpscan

    9,636Voir sur GitHub↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Ruby
    Voir sur GitHub↗9,636
  • the-robot/sqlivAvatar de the-robot

    the-robot/sqliv

    1,228Voir sur GitHub↗

    massive SQL injection vulnerability scanner

    Python
    Voir sur GitHub↗1,228
  • fcavallarin/domdigAvatar de fcavallarin

    fcavallarin/domdig

    419Voir sur GitHub↗

    DOM XSS scanner for Single Page Applications

    JavaScript
    Voir sur GitHub↗419
  • s0md3v/xsstrikeAvatar de s0md3v

    s0md3v/XSStrike

    14,752Voir sur GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Pythonwaf-detectionxssxss-bruteforce
    Voir sur GitHub↗14,752
  • hahwul/xspearAvatar de hahwul

    hahwul/XSpear

    1,357Voir sur GitHub↗

    🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

    Ruby
    Voir sur GitHub↗1,357
  • codingo/vhostscanAvatar de codingo

    codingo/VHostScan

    1,299Voir sur GitHub↗

    A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

    Pythonbugbountyctf-toolsdiscovery-service
    Voir sur GitHub↗1,299
  • d35m0nd142/lfisuiteAvatar de D35m0nd142

    D35m0nd142/LFISuite

    1,945Voir sur GitHub↗

    Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

    Python
    Voir sur GitHub↗1,945
  • charlie-belmer/nosqliAvatar de Charlie-belmer

    Charlie-belmer/nosqli

    409Voir sur GitHub↗

    NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

    Go
    Voir sur GitHub↗409
  • danmcinerney/xsscrapyAvatar de DanMcInerney

    DanMcInerney/xsscrapy

    1,742Voir sur GitHub↗

    XSS spider - 66/66 wavsep XSS detected

    Python
    Voir sur GitHub↗1,742
  • hahwul/dalfoxAvatar de hahwul

    hahwul/dalfox

    4,846Voir sur GitHub↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Gobugbountybugbounty-toolcicd-pipeline
    Voir sur GitHub↗4,846
  • joaomatosf/jexbossAvatar de joaomatosf

    joaomatosf/jexboss

    2,512Voir sur GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    Voir sur GitHub↗2,512
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Voir sur GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    Voir sur GitHub↗3,020
  • reverse-shell/routersploitAvatar de reverse-shell

    reverse-shell/routersploit

    13,151Voir sur GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    Voir sur GitHub↗13,151
  • daffainfo/allaboutbugbountyAvatar de daffainfo

    daffainfo/AllAboutBugBounty

    6,644Voir sur GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    Voir sur GitHub↗6,644
  • six2dez/reconftwAvatar de six2dez

    six2dez/reconftw

    7,226Voir sur GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    Voir sur GitHub↗7,226
  • apt69/comahawkA

    apt69/COMahawk

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • antx-code/cve-2022-21907A

    antx-code/CVE-2022-21907

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • 0xdexter0us/log4j-scannerAvatar de 0xDexter0us

    0xDexter0us/Log4J-Scanner

    102Voir sur GitHub↗

    Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

    Kotlin
    Voir sur GitHub↗102
  • anshumanpattnaik/http-request-smugglingAvatar de anshumanpattnaik

    anshumanpattnaik/http-request-smuggling

    539Voir sur GitHub↗

    HTTP Request Smuggling Detection Tool

    Python
    Voir sur GitHub↗539
  • bb00/zer0dumpB

    bb00/zer0dump

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • augustd/burp-suite-software-version-checksAvatar de augustd

    augustd/burp-suite-software-version-checks

    33Voir sur GitHub↗

    Burp extension to passively scan for applications revealing software version numbers

    Java
    Voir sur GitHub↗33
  • bbaranoff/cve-2022-0847B

    bbaranoff/CVE-2022-0847

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • benjamin-mauss/depenfusionB

    benjamin-mauss/depenfusion

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • binaryfigments/cve-2020-0674B

    binaryfigments/CVE-2020-0674

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • blackarrowsec/mssqlproxyAvatar de blackarrowsec

    blackarrowsec/mssqlproxy

    771Voir sur GitHub↗

    mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

    Python
    Voir sur GitHub↗771
  • blackcrw/wpreconAvatar de blackcrw

    blackcrw/wprecon

    20Voir sur GitHub↗

    WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.

    Go
    Voir sur GitHub↗20
  • andresriancho/w3afAvatar de andresriancho

    andresriancho/w3af

    4,850Voir sur GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    Voir sur GitHub↗4,850