Skip to content
View UWNZ's full-sized avatar

Block or report UWNZ

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Pentest Web

Bruteforce / Fuzzing Injections Open Redirect Path Traversal / LFI / RFI Bypass Charges utiles CMS SOP Bypass Clickjacking Insecure deserialization Etc...
35 repositories

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 69,253 24,916 Updated Mar 5, 2026

1337 Wordlists for Bug Bounty Hunting

Go 931 180 Updated Mar 5, 2026

List of regex for scraping secret API keys and juicy information.

723 72 Updated Aug 19, 2022

A fast, simple, recursive content discovery tool written in Rust.

Rust 7,566 604 Updated Feb 8, 2026

Directory/File, DNS and VHost busting tool written in Go

Go 13,482 1,561 Updated Mar 5, 2026

Contextual Content Discovery Tool

Go 3,107 330 Updated Apr 29, 2024

Web application fuzzer

Python 6,434 1,402 Updated Jan 21, 2026

Fast web fuzzer written in Go

Go 15,693 1,519 Updated Apr 24, 2025

A simple multi-threaded distributed SSH brute-forcing tool written in Python

Python 461 80 Updated Oct 30, 2022

AS400 login bruteforcer

Nim 7 2 Updated Jun 11, 2022

Automated All-in-One OS Command Injection Exploitation Tool

Python 5,646 922 Updated Feb 28, 2026

Automatic SQL injection and database takeover tool

Python 36,756 6,212 Updated Feb 26, 2026

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Python 3,929 413 Updated Oct 4, 2025

πŸŒ™πŸ¦Š Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Go 4,860 516 Updated Feb 28, 2026

Finding XSS during recon

Go 272 48 Updated Sep 13, 2022

πŸ”± Powerfull XSS Scanning and Parameter analysis tool&gem

Ruby 1,357 244 Updated Mar 3, 2026

Most advanced XSS scanner.

Python 14,791 2,073 Updated Apr 26, 2025

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,123 687 Updated Apr 21, 2024

An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

Shell 970 155 Updated Dec 8, 2021

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Python 3,436 732 Updated Nov 23, 2022

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

Python 657 113 Updated Apr 7, 2022

Automatic SSTI detection tool with interactive interface

Python 1,406 148 Updated Jan 17, 2026

A fast tool to scan CRLF vulnerability written in Go

Go 1,520 147 Updated Feb 23, 2026

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Python 1,915 405 Updated Apr 13, 2022

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.

Go 1,545 174 Updated Feb 28, 2026

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Go 1,814 298 Updated Jul 3, 2023

🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens

Python 6,397 769 Updated May 1, 2025

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

Python 1,631 220 Updated Mar 11, 2024