zhzyker/vulmap
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能 observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2154
- days_rel: n/a
- days_push: 1225
- n_releases_24m: 0
Adoption not part of the score
3521 stars · 576 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them. It targets common middleware and frameworks such as WebLogic, Tomcat, Shiro, Spring, Struts2, Fastjson, Solr, Elasticsearch, Jenkins, and Drupal, and supports bulk scanning of assets from Fofa, Shodan, or dismap output files.
Use cases
- scan a web app for known cve vulnerabilities
- verify an rce found on weblogic or tomcat during a pentest
- bulk scan fofa or shodan results for exploitable cves
- check if a target is vulnerable to shiro deserialization or fastjson rce
- find a quick poc-based scanner for common java middleware cves
- turn vulnerability detection into direct exploitation in one tool
When to choose
- You need a single lightweight CLI that both detects and verifies known CVEs in widely used web middleware and frameworks
- You want to batch-scan large asset lists from Fofa, Shodan, or dismap fingerprint results with multithreading
- You are doing an authorized security assessment and need fast proof-of-concept confirmation of RCE or deserialization flaws
When to avoid
- You need a full enterprise DAST/vulnerability-management platform with authenticated scanning, reporting, and continuous monitoring
- Your target technology or CVE is not on its supported list (activemq, flink, shiro, solr, struts2, tomcat, unomi, drupal, elasticsearch, fastjson, jenkins, nexus, weblogic, jboss, spring, thinkphp)
- You require up-to-date coverage of newly published CVEs, since the project has not seen a release since April 2023
Facets
cli-tool · maturity maintenance
vulnerability-scanning penetration-testing security osint security penetration-testing windows cross-platform cli python exploit cve rce vulnerability-scanner pentest-tool web-security fofa shodan batch-scanning red-team linux macos docker
2 sources
- readme: https://github.com/zhzyker/vulmap · fetched 2026-08-28 · 9a909b670293
- homepage: https://github.com/zhzyker/vulmap · fetched 2026-08-29 · c2f8173a9229
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| zhzyker/vulmap | main | 23 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem