Web Vulnerability Scanners
Web vulnerability scanners test HTTP/HTTPS endpoints for injection flaws, broken authentication, sensitive data exposure, and logic errors. Use these tools to continuously monitor your public-facing applications before attackers do.
Important Web Vulnerabilities Scanners
Online Generic SQL Injection Vulnerability Scanner
Detect SQL Injection vulnerabilities in your web applications
Free and Online Generic XSS Scanner
XSS Vulnerability is a type of vulnerability typically found in web applications. It occurs when user input data is not correctly filtered or sanitized before being returned to the end-user.
Generic SSRF Vulnerability Scanner
Server-side request forgery (SSRF), is a vulnerability that allows an attacker to execute unauthorized requests from the perspective of the webserver. SSRF can be used to access sensitive data, such as internal network resources and user data, or to launch attacks on other systems from the webserver.The impact of SSRF attacks can be significant. They can allow attackers to arbitrary command execution, access internal apps, and even scan ports in the local network.
Generic Server Side Template Injection (SSTI) Vulnerability Scanner
Detects 'Server Side Template Injection (SSTI)' vulnerability in Web Application. Identifies injectable template contexts that allow server-side evaluation of attacker-controlled expressions, enabling data exposure or remote code execution if exploited.
Online Generic File Inclusion - LFI/RFI Vulnerability Scanner
File inclusion vulnerabilities are a type of vulnerability that occurs when an attacker is able to include a file, usually through using inputs on the webserver. These vulnerabilities can lead to information disclosure, arbitrary code execution, and full system compromise.
Generic Blind XXE Scanner
Generic Blind XXE Scanner
Generic Command Injection Vulnerability Scanner
A command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.
HTTP Header Command Injection Vulnerability Fuzz & Scanner
You can fuzz HTTP headers for command injection using this tool.
Cache Poisoning to Stored XSS Vulnerability Scanner
This scanner identifies vulnerabilities where cache poisoning could lead to stored XSS, enabling attackers to inject malicious scripts that are executed when the cached content is served.
Generic Web Application Source Code Disclosure Scanner
Detects 'Source Code Disclosure' vulnerability in Web Application affecting exposed source/config files and repository artifacts. This scanner finds accessible source files, backups, and repository metadata that may reveal sensitive code and secrets.
Generic Error Based SQL Injection Scanner
This scanner detects the use of error-based SQL injection in digital assets. It helps identify vulnerabilities that may allow attackers to execute SQL errors for unauthorized data access or manipulation, providing critical intelligence to protect against cyber threats.
Generic Code Injection Vulnerability Scanner
Detects 'Code Injection' vulnerability. This scanner identifies weaknesses in web applications, built with technologies like PHP, Ruby, Python, Java, and ASP, where an attacker can introduce and execute arbitrary code. Detecting this critical flaw prevents unauthorized server access and potential system compromise.
Halo ITSM SQL Injection Scanner
Detects 'SQL Injection' vulnerability in Halo ITSM.
Windows LFI Vulnerability Scanner
Detect and Protect Against Windows LFI Vulnerabilities
Generic Linux LFI Detection Scanner
Identify and Mitigate Local File Inclusion Vulnerabilities in Linux Systems
J2EE LFI Vulnerability Scanner
Detect potential Local File Inclusion (LFI) vulnerabilities within J2EE applications, focusing on unauthorized access to critical files such as web.xml, which could lead to sensitive information disclosure.
CPAS Management System SQL Injection Scanner
Detects 'SQL Injection' vulnerability in CPAS Management System affects v. 4. This scanner identifies critical flaws allowing unauthorized data retrieval and server compromise through SQL queries.
Fronsetiav Cross-Site Scripting Scanner
Targets the 'WSDL Location' parameter in show_operations.jsp, enabling attackers to inject malicious scripts that execute in victims' browsers.
Top 38 Parameters XSS Vulnerability Scanner
Detecting Cross-Site Scripting (XSS) Through Top 38 Parameters
CVE-2011-0518 Scanner
CVE-2011-0518 Scanner - Remote Code Execution vulnerability in LotusCMS
CVE-2026-23693 Scanner
CVE-2026-23693 Scanner - Unauthorized Admin Access vulnerability in ElementsKit Lite
Unix/Linux OS Command Injection Scanner
This scanner detects the use of Unix/Linux Operating Systems in digital assets by identifying potential OS command injections. These injections can lead to arbitrary command execution, allowing full server compromise and more.
CVE-2023-50839 Scanner
CVE-2023-50839 Scanner - SQL Injection vulnerability in JS Help Desk
Windows OS Command Injection Scanner
This scanner detects the use of Windows OS Command Injection in digital assets. Identify potential vulnerabilities that could lead to arbitrary command execution, exposing systems to risks such as unauthorized access and data exfiltration.
Error-Based SQL Injection Vulnerability Scanner
This scanner identifies SQL Injection vulnerabilities through error messages returned by the server, indicating improper input validation and sanitization in handling SQL queries.
CVE-2024-51211 Scanner
CVE-2024-51211 Scanner - SQL Injection vulnerability in openSIS Classic
Windows Fuzzing Scanner
This scanner detect Local File Inclusion (LFI) vulnerabilities in Windows systems by fuzzing access to the win.ini file.
CVE-2026-57582 Scanner
CVE-2026-57582 Scanner - Cross-Site Scripting (XSS) vulnerability in GeoNetwork
Generic Remote File Inclusion Scanner
This scanner detects the use of Generic Remote File Inclusion in digital assets. It identifies vulnerabilities to prevent unauthorized remote file execution, enhancing security.
Linux Local File Inclusion Fuzzing Scanner
Linux Local File Inclusion Fuzzing Scanner
Generic XXE Vulnerability Scanner
XML external entity injection (also known as XXE) is a vulnerability that can be exploited by attackers to read and write files on the target server, as well as access sensitive data. XXE is a type of injection attack that occurs when an attacker injects XML input into an application that uses XML processing. This can allow the attacker to access files on the server and even execute arbitrary code.
Full Response SSRF Scanner
This scanner detects the use of Full Response SSRF in digital assets. It helps identify potential vulnerabilities from Server-Side Request Forgery that may expose sensitive internal services.
Linux Local File Inclusion Fuzz Scanner
This scanner detects the use of Local File Inclusion vulnerability in Linux systems. It helps identify potential LFI threats that could allow attackers to read sensitive files on Linux servers.
Windows Local File Inclusion Fuzz Scanner
This scanner detects the use of Local File Inclusion vulnerabilities in Windows systems.
Generic Blind OS Command Injection Scanner
This scanner detects the use of Blind OS Command Injection vulnerabilities in digital assets. Identifying these vulnerabilities is crucial as they could allow attackers to execute arbitrary commands on the server, posing significant security risks. Ensuring the safety of your applications is essential in maintaining robust security protocols.
Generic XPath Injection Vulnerability Scanner
Detects 'XPath Injection' vulnerability in Generic Web Application. Identifies inputs that allow malicious XPath payloads to alter XML query logic and access or manipulate sensitive data. Useful for finding injection points in XML-processing endpoints.
CVE-2018-17283 Scanner
CVE-2018-17283 Scanner - SQL Injection vulnerability in Zoho ManageEngine OpManager
Leantime Cross-Site Scripting Scanner
Detects 'Cross-Site Scripting (XSS)' vulnerability in Leantime.
Generic Local File Inclusion (LFI) Scanner
This scanner detects the use of Local File Inclusion (LFI) in digital assets. It helps in identifying misconfigurations and vulnerabilities in web applications that can be exploited by attackers.
Online Generic Fast SQL Injection Vulnerability Scanner
Detect SQL Injection vulnerabilities fastly
HTTPBin Content-Type Reflection Cross-Site Scripting Scanner
Detects Cross-Site Scripting vulnerability in HTTPBin’s Content-Type handling. Identifies reflected script injection caused by unsanitized header-based input.
Generic LDAP Injection Vulnerability Scanner
Detects 'LDAP Injection' vulnerability in LDAP. Scans for unsanitized LDAP query inputs that allow attackers to manipulate search filters, access or modify directory data, and perform unauthorized queries. Useful for quickly identifying LDAP query injection risks in web apps and directory-backed services.
Generic NoSQL Injection Vulnerability Scanner
Detects 'NoSQL Injection' vulnerability in NoSQL Database. This scanner identifies injection points where user-supplied input can manipulate NoSQL query structures, enabling unauthorized data access or modification.
window.name DOM XSS Scanner
Various research and studies identified that up to 50% of websites are vulnerable to DOM Based XSS vulnerability.
Cache Poison Fuzzing Scanner
Cache Poison Fuzzing Scanner
Generic XInclude Injection Scanner
This scanner detects the use of XInclude in digital assets. This is valuable for identifying potential security vulnerabilities related to XXE attacks, which can lead to information disclosure and potential system compromise.
Balada Injector Malware Scanner
Identify the stealthy Balada Injector malware within your network. Our scanner is your first line of defense, designed to uncover and address this sophisticated threat efficiently.
Generic Python Code Injection Scanner
This scanner detects the use of Python Code Injection in digital assets. It helps identify vulnerabilities that could allow an attacker to execute arbitrary Python code on a server. This is crucial for maintaining secure systems and preventing unauthorized access.
SSRF via Proxy Unsafe Fuzzing Scanner
SSRF via Proxy Unsafe Fuzzing Scanner
CNVD-2024-33023 Scanner
CNVD-2024-33023 Scanner - SQL Injection (SQLi) vulnerability in UFIDA U8 Cloud
JeePlus CMS SQL Injection Scanner
Detects 'SQL Injection' vulnerability in JeePlus CMS allowing unauthorized data access or modification.
CVE-2025-27892 Scanner
CVE-2025-27892 Scanner - SQL Injection vulnerability in Shopware
CVE-2024-51228 Scanner
CVE-2024-51228 Scanner - Remote Code Execution vulnerability in TOTOLINK CX-A3002RU
CVE-2023-45826 Scanner
CVE-2023-45826 Scanner - SQL Injection (SQLi) vulnerability in Leantime
Generic CRLF Injection Vulnerability Scanner
The CRLF (\r\n) abbreviation refers to Carriage Return and Line Feed. A CRLF injection attack is a type of injection attack that exploits the combination of a carriage return and line feed characters, which are used to end a line of text in a file or command.
X-Forwarded-For 403-forbidden Bypass Fuzz & Scanner
Detect 403 forbidden endpoint bypass behind Nginx/Apache proxy & load balancers, based on X-Forwarded-For header.
Generic HTTP Response Splitting Scanner
Detects 'HTTP Response Splitting' vulnerability in HTTP server and web applications that accept untrusted header input. Useful for finding header injection points where crafted CRLF sequences allow an attacker to manipulate response headers or create additional responses.
CVE-2024-6892 Scanner
CVE-2024-6892 Scanner - Cross-Site Scripting (XSS) vulnerability in Journyx
Reflected XSS from Header Scanner
Detects 'Cross-Site Scripting (XSS)' vulnerability in headers that may be reflected in the HTML provided.
Run all Web Vulnerabilities checks at once.
S4E covers 109+ scanners in this category with continuous monitoring and full remediation guidance.
Start Free Scan →