Fuzzing Open Source Projects

Browse 418 Fuzzing open source projects, ranked by GitHub stars. Find the most popular Fuzzing tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 418 projects
116,474 stars

Hack-with-Github/Awesome-Hacking

A collection of various awesome lists for hackers, pentesters and security researchers

Metrics details
Stars116,474
72,302 stars

danielmiessler/SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Metrics details
Stars72,302
16,399 stars

ffuf/ffuf

Fast web fuzzer written in Go

Metrics details
Stars16,399
14,521 stars

maurosoria/dirsearch

Web path scanner

Metrics details
Stars14,521
12,450 stars

google/oss-fuzz

OSS-Fuzz - continuous fuzzing for open source software.

Metrics details
Stars12,450
10,493 stars

foundry-rs/foundry

Foundry is a blazing fast, portable and modular toolkit for Ethereum application development written in Rust.

Metrics details
Stars10,493
9,046 stars

spacejam/sled

the champagne of beta embedded databases

Metrics details
Stars9,046
8,795 stars

HypothesisWorks/hypothesis

The property-based testing library for Python

Metrics details
Stars8,795
8,386 stars

TheKingOfDuck/fuzzDicts

You Know, For WEB Fuzzing !

Metrics details
Stars8,386
7,866 stars

six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Metrics details
Stars7,866
6,663 stars

AFLplusplus/AFLplusplus

The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

Metrics details
Stars6,663
6,273 stars

google/syzkaller

syzkaller is an unsupervised coverage-guided kernel fuzzer

Metrics details
Stars6,273
5,876 stars

secfigo/Awesome-Fuzzing

A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.

Metrics details
Stars5,876
5,709 stars

elceef/dnstwist

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Metrics details
Stars5,709
5,582 stars

google/clusterfuzz

Scalable fuzzing infrastructure.

Metrics details
Stars5,582
5,070 stars

dubzzz/fast-check

Property based testing framework for JavaScript (like QuickCheck) written in TypeScript

Metrics details
Stars5,070
4,853 stars

dvyukov/go-fuzz

Randomized testing for Go

Metrics details
Stars4,853
4,077 stars

fwupd/fwupd

A system daemon to allow session software to update firmware

Metrics details
Stars4,077
3,959 stars

1N3/IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

Metrics details
Stars3,959
3,854 stars

arainho/awesome-api-security

A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

Metrics details
Stars3,854
3,807 stars

antonio-morales/Fuzzing101

An step by step fuzzing tutorial. A GitHub Security Lab initiative

Metrics details
Stars3,807
3,786 stars

evyatarmeged/Raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning

Metrics details
Stars3,786
3,778 stars

google/fuzzing

Tutorials, examples, discussions, research proposals, and other resources related to fuzzing

Metrics details
Stars3,778
3,555 stars

unicode-org/icu

The home of the ICU project source code.

Metrics details
Stars3,555
3,366 stars

google/honggfuzz

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Metrics details
Stars3,366
3,252 stars

rtcatc/Packer-Fuzzer

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Metrics details
Stars3,252
3,198 stars

six2dez/OneListForAll

Rockyou for web fuzzing

Metrics details
Stars3,198
3,160 stars

crytic/echidna

Ethereum smart contract fuzzer

Metrics details
Stars3,160
3,136 stars

devanshbatham/ParamSpider

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Metrics details
Stars3,136
2,924 stars

microsoft/restler-fuzzer

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.

Metrics details
Stars2,924
2,880 stars

dloss/python-pentest-tools

Python tools for penetration testers

Metrics details
Stars2,880
2,828 stars

microsoft/onefuzz

A self-hosted Fuzzing-As-A-Service platform

Metrics details
Stars2,828
2,768 stars

gh0stkey/Web-Fuzzing-Box

Web Fuzzing Box - Web 模糊测试字典与一些Payloads

Metrics details
Stars2,768
2,767 stars

wcventure/FuzzingPaper

Recent Fuzzing Paper

Metrics details
Stars2,767
2,625 stars

asatarin/testing-distributed-systems

Curated list of resources on testing distributed systems

Metrics details
Stars2,625
2,608 stars

AFLplusplus/LibAFL

Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...

Metrics details
Stars2,608
2,584 stars

googleprojectzero/winafl

A fork of AFL for fuzzing Windows binaries

Metrics details
Stars2,584
2,562 stars

Ignitetechnologies/BurpSuite-For-Pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and completely with "BurpSuite".

Metrics details
Stars2,562
2,349 stars

jtpereyda/boofuzz

A fork and successor of the Sulley Fuzzing Framework

Metrics details
Stars2,349
2,314 stars

googleprojectzero/fuzzilli

A JavaScript Engine Fuzzer

Metrics details
Stars2,314
2,293 stars

p0dalirius/Coercer

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

Metrics details
Stars2,293
2,290 stars

Escapingbug/awesome-browser-exploit

awesome list of browser exploitation tutorials

Metrics details
Stars2,290
2,231 stars

felixguendling/cista

Cista is a simple, high-performance, zero-copy C++ serialization & reflection library.

Metrics details
Stars2,231
2,065 stars

insightglacier/Dictionary-Of-Pentesting

Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。

Metrics details
Stars2,065
2,052 stars

yahoo/gryffin

Gryffin is a large scale web security scanning platform.

Metrics details
Stars2,052
2,033 stars

0xSobky/HackVault

A container repository for my public web hacks!

Metrics details
Stars2,033
1,905 stars

a3vilc0de/PentesterSpecialDict

Dictionary for penetration testers happy hacker

Metrics details
Stars1,905
1,851 stars

rust-fuzz/cargo-fuzz

Command line helpers for fuzzing

Metrics details
Stars1,851
1,834 stars

rust-fuzz/afl.rs

🐇 Fuzzing Rust code with American Fuzzy Lop

Metrics details
Stars1,834
1,821 stars

parsiya/Hacking-with-Go

Golang for Security Professionals

Metrics details
Stars1,821
1,788 stars

googleprojectzero/domato

DOM fuzzer

Metrics details
Stars1,788
1,778 stars

0vercl0k/wtf

wtf is a distributed, code-coverage guided, customizable, cross-platform snapshot-based fuzzer designed for attacking user and / or kernel-mode targets running on Microsoft Windows and Linux user-mode (experimental!).

Metrics details
Stars1,778
1,741 stars

sqlancer/sqlancer

Automated testing to find logic and performance bugs in database systems

Metrics details
Stars1,741
1,722 stars

bowu678/php_bugs

PHP代码审计分段讲解

Metrics details
Stars1,722
1,706 stars

cn0xroot/RFSec-ToolKit

RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith

Metrics details
Stars1,706
1,681 stars

crossbario/autobahn-testsuite

Autobahn WebSocket protocol testsuite

Metrics details
Stars1,681
1,678 stars

swisskyrepo/GraphQLmap

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

Metrics details
Stars1,678
1,674 stars

marin-m/pbtk

A toolset for reverse engineering and fuzzing Protobuf-based apps

Metrics details
Stars1,674
1,648 stars

google/atheris

Metrics details
Stars1,648
1,630 stars

veo/vscan

开源、轻量、快速、跨平台 的网站漏洞扫描工具,帮助您快速检测网站安全隐患。功能 端口扫描(port scan) 指纹识别(fingerprint) 漏洞检测(nday check) 智能爆破 (admin brute) 敏感文件扫描(file fuzz)

Metrics details
Stars1,630
1-60 of 418 projects
Get A Weekly Email With Trending Fuzzing Projects
Stay updated on Fuzzing plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.