Back to Toolkit

Web Vulnerability Testing

Web Vulnerability Testing is a reference category for Red Team work. Select an upstream project only after confirming scope, authorization, license, and maintenance status.

8 published reference entries · reviewed catalogue metadata is shown on every card.

Reference only: these are upstream references; VectrionX does not execute tools or host payloads. Use only in authorized environments and follow the project license and documentation.
Worked interpretation example: if an upstream reference reports an exposed service, record the source and timestamp first; treat it as an observation, validate it against an authoritative source, and only then assign severity or an owner.

OWASP ZAP

Vulnerability Scanning

The world’s most widely used web app scanner. Free and open source active vulnerability scanner.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Web ScannerVulnerabilityProxy+1

Nikto

Vulnerability Scanning

An open-source web server scanner which performs comprehensive tests against web servers for multiple items.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Web ScannerVulnerabilityPerl

NoSQLMap

NoSQL Assessment

An open source Python tool designed to audit for as well as automate injection attacks and exploit default configuration weaknesses in NoSQL databases.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
NoSQLDatabaseVulnerability Scanner+1

SQLmap

SQL Injection Testing

Automatic SQL injection and database takeover tool.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
SQL InjectionDatabaseScanner+1

XSStrike

XSS Testing

An advanced Cross-Site Scripting (XSS) scanner with intelligent payload generation and context analysis.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
XSSWebScanner+1

Commix

Command Injection Testing

An automated tool for testing web applications for OS command injection vulnerabilities.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Command InjectionWebScanner+1

Burp Suite Community Edition

Proxies

An integrated platform for performing security testing of web applications.

Provenance
community software
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
WebProxyVulnerability+2
Intermediate

testssl.sh

Vulnerability Scanning

A free command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as some cryptographic flaws.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
WebSSLTLS+4