Web Application
Nuclei
Template-based vulnerability scanner with huge community template set.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Fast, repeatable vulnerability checks across many hosts/URLs.
How
Feed targets; select severity/tags; keep templates updated; verify findings manually.
Why
Massive coverage with YAML templates — industry favorite for bug bounty/recon pipelines.
Commands & usage
nuclei -u https://example.com
nuclei -l urls.txt -severity critical,high -o findings.txt
nuclei -u https://example.com -t http/cves/ -as
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
OWASP
Recipes
Tags
Related in Web Application
ffuf
Fast web fuzzer for directories, vhosts, parameters, and more.
Gobuster
Directory/DNS/vhost brute-forcing tool written in Go.
Feroxbuster
Recursive content discovery tool with smart filtering.
dirsearch
Feature-rich web path scanner in Python.
Wfuzz
Flexible web application fuzzer for params, headers, auth, etc.
Nikto
Classic web server scanner for dangerous files, misconfigs, outdated software.