S4E just found a critical-severity finding from cve-2024-42009 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
109 tools·Free, no account required

Web Vulnerability Scanners

Web vulnerability scanners test HTTP/HTTPS endpoints for injection flaws, broken authentication, sensitive data exposure, and logic errors. Use these tools to continuously monitor your public-facing applications before attackers do.

By the numbers
109
Web Vulnerabilities scanners
in this category
291.5k
Automated runs
scans executed here
372.4k
Assets scanned
verified across S4E
NewestCVE-2026-0561 Scanner
Run Full Scan →← All categories
Network VulnerabilitiesMisconfigurationInformation ScansExposed PanelsProduct CVEs (Web)Product CVEs (Network)DNS ControlsSSL Controls
Featured in this category

Important Web Vulnerabilities Scanners

Browse all 109 tools →
high7.3

Online Generic SQL Injection Vulnerability Scanner

Detect SQL Injection vulnerabilities in your web applications

~1800sSingle assetBulk scanAPI
Nov 16, 2021
medium6.1

Free and Online Generic XSS Scanner

XSS Vulnerability is a type of vulnerability typically found in web applications. It occurs when user input data is not correctly filtered or sanitized before being returned to the end-user.

~60sSingle assetBulk scanAPI
Mar 24, 2022
high7.3

Generic SSRF Vulnerability Scanner

Server-side request forgery (SSRF), is a vulnerability that allows an attacker to execute unauthorized requests from the perspective of the webserver. SSRF can be used to access sensitive data, such as internal network resources and user data, or to launch attacks on other systems from the webserver.The impact of SSRF attacks can be significant. They can allow attackers to arbitrary command execution, access internal apps, and even scan ports in the local network.

~10sSingle assetBulk scanAPI
Mar 24, 2022
high8.6

Generic Server Side Template Injection (SSTI) Vulnerability Scanner

Detects 'Server Side Template Injection (SSTI)' vulnerability in Web Application. Identifies injectable template contexts that allow server-side evaluation of attacker-controlled expressions, enabling data exposure or remote code execution if exploited.

~600sSingle assetAPI
Nov 5, 2025
high7.3

Online Generic File Inclusion - LFI/RFI Vulnerability Scanner

File inclusion vulnerabilities are a type of vulnerability that occurs when an attacker is able to include a file, usually through using inputs on the webserver. These vulnerabilities can lead to information disclosure, arbitrary code execution, and full system compromise.

~10sSingle assetBulk scanAPI
Mar 24, 2022
high8.0

Generic Blind XXE Scanner

Generic Blind XXE Scanner

~10sSingle assetBulk scanAPI
Jan 15, 2022
critical9.8

Generic Command Injection Vulnerability Scanner

A command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.

~10sSingle assetBulk scanAPI
Mar 24, 2022
critical10.0

HTTP Header Command Injection Vulnerability Fuzz & Scanner

You can fuzz HTTP headers for command injection using this tool.

~300sSingle assetBulk scanAPI
May 14, 2021
high8.0

Cache Poisoning to Stored XSS Vulnerability Scanner

This scanner identifies vulnerabilities where cache poisoning could lead to stored XSS, enabling attackers to inject malicious scripts that are executed when the cached content is served.

~60sSingle assetBulk scanAPI
Feb 12, 2024
medium6.5

Generic Web Application Source Code Disclosure Scanner

Detects 'Source Code Disclosure' vulnerability in Web Application affecting exposed source/config files and repository artifacts. This scanner finds accessible source files, backups, and repository metadata that may reveal sensitive code and secrets.

~10sSingle assetBulk scanAPI
Nov 2, 2025
critical9.0

Generic Error Based SQL Injection Scanner

This scanner detects the use of error-based SQL injection in digital assets. It helps identify vulnerabilities that may allow attackers to execute SQL errors for unauthorized data access or manipulation, providing critical intelligence to protect against cyber threats.

~10sSingle assetBulk scanAPI
Nov 8, 2025
critical9.8

Generic Code Injection Vulnerability Scanner

Detects 'Code Injection' vulnerability. This scanner identifies weaknesses in web applications, built with technologies like PHP, Ruby, Python, Java, and ASP, where an attacker can introduce and execute arbitrary code. Detecting this critical flaw prevents unauthorized server access and potential system compromise.

~10sSingle assetBulk scanAPI
Nov 2, 2025
critical9.0

Halo ITSM SQL Injection Scanner

Detects 'SQL Injection' vulnerability in Halo ITSM.

~60sSingle assetBulk scanAPI
Apr 4, 2025
high8.1

Windows LFI Vulnerability Scanner

Detect and Protect Against Windows LFI Vulnerabilities

~15sSingle assetBulk scanAPI
May 14, 2021
high8.1

Generic Linux LFI Detection Scanner

Identify and Mitigate Local File Inclusion Vulnerabilities in Linux Systems

~15sSingle assetBulk scanAPI
May 14, 2021
high8.0

J2EE LFI Vulnerability Scanner

Detect potential Local File Inclusion (LFI) vulnerabilities within J2EE applications, focusing on unauthorized access to critical files such as web.xml, which could lead to sensitive information disclosure.

~60sSingle assetBulk scanAPI
Feb 12, 2024
high8.0

CPAS Management System SQL Injection Scanner

Detects 'SQL Injection' vulnerability in CPAS Management System affects v. 4. This scanner identifies critical flaws allowing unauthorized data retrieval and server compromise through SQL queries.

~60sSingle assetBulk scanAPI
Jan 7, 2025
high8.3

Fronsetiav Cross-Site Scripting Scanner

Targets the 'WSDL Location' parameter in show_operations.jsp, enabling attackers to inject malicious scripts that execute in victims' browsers.

~10sSingle assetBulk scanAPI
Dec 1, 2024
high7.4

Top 38 Parameters XSS Vulnerability Scanner

Detecting Cross-Site Scripting (XSS) Through Top 38 Parameters

~60sSingle assetBulk scanAPI
Feb 12, 2024
critical10.0

CVE-2011-0518 Scanner

CVE-2011-0518 Scanner - Remote Code Execution vulnerability in LotusCMS

~10sBulk scanAPI
Oct 15, 2025
critical10.0

CVE-2026-23693 Scanner

CVE-2026-23693 Scanner - Unauthorized Admin Access vulnerability in ElementsKit Lite

~10sBulk scanAPI
Sep 7, 2026
critical9.8

Unix/Linux OS Command Injection Scanner

This scanner detects the use of Unix/Linux Operating Systems in digital assets by identifying potential OS command injections. These injections can lead to arbitrary command execution, allowing full server compromise and more.

~10sSingle assetBulk scanAPI
Jul 23, 2026
critical9.8

CVE-2023-50839 Scanner

CVE-2023-50839 Scanner - SQL Injection vulnerability in JS Help Desk

~10sSingle assetBulk scanAPI
Mar 12, 2026
critical9.8

Windows OS Command Injection Scanner

This scanner detects the use of Windows OS Command Injection in digital assets. Identify potential vulnerabilities that could lead to arbitrary command execution, exposing systems to risks such as unauthorized access and data exfiltration.

~10sSingle assetBulk scanAPI
Jul 23, 2026
critical9.8

Error-Based SQL Injection Vulnerability Scanner

This scanner identifies SQL Injection vulnerabilities through error messages returned by the server, indicating improper input validation and sanitization in handling SQL queries.

~60sSingle assetBulk scanAPI
Feb 12, 2024
critical9.8

CVE-2024-51211 Scanner

CVE-2024-51211 Scanner - SQL Injection vulnerability in openSIS Classic

~60sSingle assetBulk scanAPI
May 27, 2025
high8.5

Windows Fuzzing Scanner

This scanner detect Local File Inclusion (LFI) vulnerabilities in Windows systems by fuzzing access to the win.ini file.

~60sSingle assetBulk scanAPI
Sep 12, 2025
high8.2

CVE-2026-57582 Scanner

CVE-2026-57582 Scanner - Cross-Site Scripting (XSS) vulnerability in GeoNetwork

~10sBulk scanAPI
Sep 2, 2026
high8.0

Generic Remote File Inclusion Scanner

This scanner detects the use of Generic Remote File Inclusion in digital assets. It identifies vulnerabilities to prevent unauthorized remote file execution, enhancing security.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.5

Linux Local File Inclusion Fuzzing Scanner

Linux Local File Inclusion Fuzzing Scanner

~60sSingle assetBulk scanAPI
Oct 8, 2024
high7.5

Generic XXE Vulnerability Scanner

XML external entity injection (also known as XXE) is a vulnerability that can be exploited by attackers to read and write files on the target server, as well as access sensitive data. XXE is a type of injection attack that occurs when an attacker injects XML input into an application that uses XML processing. This can allow the attacker to access files on the server and even execute arbitrary code.

~10sSingle assetBulk scanAPI
Mar 24, 2022
high7.5

Full Response SSRF Scanner

This scanner detects the use of Full Response SSRF in digital assets. It helps identify potential vulnerabilities from Server-Side Request Forgery that may expose sensitive internal services.

~60sSingle assetBulk scanAPI
Oct 8, 2024
high7.5

Linux Local File Inclusion Fuzz Scanner

This scanner detects the use of Local File Inclusion vulnerability in Linux systems. It helps identify potential LFI threats that could allow attackers to read sensitive files on Linux servers.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.5

Windows Local File Inclusion Fuzz Scanner

This scanner detects the use of Local File Inclusion vulnerabilities in Windows systems.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.5

Generic Blind OS Command Injection Scanner

This scanner detects the use of Blind OS Command Injection vulnerabilities in digital assets. Identifying these vulnerabilities is crucial as they could allow attackers to execute arbitrary commands on the server, posing significant security risks. Ensuring the safety of your applications is essential in maintaining robust security protocols.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.5

Generic XPath Injection Vulnerability Scanner

Detects 'XPath Injection' vulnerability in Generic Web Application. Identifies inputs that allow malicious XPath payloads to alter XML query logic and access or manipulate sensitive data. Useful for finding injection points in XML-processing endpoints.

~10sSingle assetBulk scanAPI
Nov 3, 2025
high7.5

CVE-2018-17283 Scanner

CVE-2018-17283 Scanner - SQL Injection vulnerability in Zoho ManageEngine OpManager

~60sSingle assetBulk scanAPI
May 22, 2025
high7.5

Leantime Cross-Site Scripting Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Leantime.

~10sSingle assetBulk scanAPI
Feb 25, 2025
high7.5

Generic Local File Inclusion (LFI) Scanner

This scanner detects the use of Local File Inclusion (LFI) in digital assets. It helps in identifying misconfigurations and vulnerabilities in web applications that can be exploited by attackers.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.3

Online Generic Fast SQL Injection Vulnerability Scanner

Detect SQL Injection vulnerabilities fastly

~60sSingle assetBulk scanAPI
Aug 15, 2022
high7.2

HTTPBin Content-Type Reflection Cross-Site Scripting Scanner

Detects Cross-Site Scripting vulnerability in HTTPBin’s Content-Type handling. Identifies reflected script injection caused by unsanitized header-based input.

~10sSingle assetBulk scanAPI
Apr 2, 2025
high7.2

Generic LDAP Injection Vulnerability Scanner

Detects 'LDAP Injection' vulnerability in LDAP. Scans for unsanitized LDAP query inputs that allow attackers to manipulate search filters, access or modify directory data, and perform unauthorized queries. Useful for quickly identifying LDAP query injection risks in web apps and directory-backed services.

~10sSingle assetBulk scanAPI
Nov 2, 2025
high7.1

Generic NoSQL Injection Vulnerability Scanner

Detects 'NoSQL Injection' vulnerability in NoSQL Database. This scanner identifies injection points where user-supplied input can manipulate NoSQL query structures, enabling unauthorized data access or modification.

~10sSingle assetBulk scanAPI
Nov 3, 2025
high7.1

window.name DOM XSS Scanner

Various research and studies identified that up to 50% of websites are vulnerable to DOM Based XSS vulnerability.

~15sSingle assetAPI
May 16, 2021
high7.0

Cache Poison Fuzzing Scanner

Cache Poison Fuzzing Scanner

~60sSingle assetBulk scanAPI
Oct 8, 2024
high7.0

Generic XInclude Injection Scanner

This scanner detects the use of XInclude in digital assets. This is valuable for identifying potential security vulnerabilities related to XXE attacks, which can lead to information disclosure and potential system compromise.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.0

Balada Injector Malware Scanner

Identify the stealthy Balada Injector malware within your network. Our scanner is your first line of defense, designed to uncover and address this sophisticated threat efficiently.

~10sSingle assetBulk scanAPI
Feb 10, 2024
high7.0

Generic Python Code Injection Scanner

This scanner detects the use of Python Code Injection in digital assets. It helps identify vulnerabilities that could allow an attacker to execute arbitrary Python code on a server. This is crucial for maintaining secure systems and preventing unauthorized access.

~10sSingle assetBulk scanAPI
Nov 8, 2025
high7.0

SSRF via Proxy Unsafe Fuzzing Scanner

SSRF via Proxy Unsafe Fuzzing Scanner

~60sSingle assetBulk scanAPI
Oct 8, 2024
high7.0

CNVD-2024-33023 Scanner

CNVD-2024-33023 Scanner - SQL Injection (SQLi) vulnerability in UFIDA U8 Cloud

~60sSingle assetBulk scanAPI
Jan 7, 2025
high7.0

JeePlus CMS SQL Injection Scanner

Detects 'SQL Injection' vulnerability in JeePlus CMS allowing unauthorized data access or modification.

~10sSingle assetBulk scanAPI
Jan 2, 2025
medium6.8

CVE-2025-27892 Scanner

CVE-2025-27892 Scanner - SQL Injection vulnerability in Shopware

~60sSingle assetBulk scanAPI
Apr 23, 2025
medium6.8

CVE-2024-51228 Scanner

CVE-2024-51228 Scanner - Remote Code Execution vulnerability in TOTOLINK CX-A3002RU

~60sSingle assetBulk scanAPI
Mar 6, 2025
medium6.5

CVE-2023-45826 Scanner

CVE-2023-45826 Scanner - SQL Injection (SQLi) vulnerability in Leantime

~10sSingle assetBulk scanAPI
Feb 25, 2025
medium6.5

Generic CRLF Injection Vulnerability Scanner

The CRLF (\r\n) abbreviation refers to Carriage Return and Line Feed. A CRLF injection attack is a type of injection attack that exploits the combination of a carriage return and line feed characters, which are used to end a line of text in a file or command.

~10sSingle assetBulk scanAPI
Mar 24, 2022
medium6.5

X-Forwarded-For 403-forbidden Bypass Fuzz & Scanner

Detect 403 forbidden endpoint bypass behind Nginx/Apache proxy & load balancers, based on X-Forwarded-For header.

~60sSingle assetBulk scanAPI
May 20, 2022
medium6.5

Generic HTTP Response Splitting Scanner

Detects 'HTTP Response Splitting' vulnerability in HTTP server and web applications that accept untrusted header input. Useful for finding header injection points where crafted CRLF sequences allow an attacker to manipulate response headers or create additional responses.

~10sSingle assetBulk scanAPI
Nov 2, 2025
medium6.1

CVE-2024-6892 Scanner

CVE-2024-6892 Scanner - Cross-Site Scripting (XSS) vulnerability in Journyx

~10sSingle assetBulk scanAPI
Mar 12, 2025
medium6.1

Reflected XSS from Header Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in headers that may be reflected in the HTML provided.

~10sSingle assetBulk scanAPI
Jun 26, 2025

Run all Web Vulnerabilities checks at once.

S4E covers 109+ scanners in this category with continuous monitoring and full remediation guidance.

Start Free Scan →