The tool is officially done and the repository is live for everyone to access.
Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments.
KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, and deep scans to check for known CVEs, parameter sanitization issues, and flaws like SQL injection.
Instead of just giving you a standard report showing what's broken, it actually outputs a hardening matrix with the exact configuration patches for Nginx, Apache, and Laravel so you can secure your website straight away. It also includes an automated setup script to link the tool globally to your terminal environment.
Quick start:
Go check out the repository, read through the documentation, and drop a star on the project:
https://github.com/PicasoTheDeal/KASCVE
Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments.
KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, and deep scans to check for known CVEs, parameter sanitization issues, and flaws like SQL injection.
Instead of just giving you a standard report showing what's broken, it actually outputs a hardening matrix with the exact configuration patches for Nginx, Apache, and Laravel so you can secure your website straight away. It also includes an automated setup script to link the tool globally to your terminal environment.
Quick start:
git clone https://github.com/PicasoTheDeal/KASCVE.git
cd KASCVE && sudo ./install.sh
KASCVE targetdomain.com
Go check out the repository, read through the documentation, and drop a star on the project:
https://github.com/PicasoTheDeal/KASCVE
GitHub
GitHub - PicasoTheDeal/KASCVE: Automated attack surface mapper & CVE evaluator. Packed with multi-tier SecLists directory fuzzing…
Automated attack surface mapper & CVE evaluator. Packed with multi-tier SecLists directory fuzzing, forgotten staging asset identification, and prioritized defensive hardening blueprints fo...
Tetstack
urm sooo besoccer is also vulnerable, I think i made the wrong tool but as long as i say it is for defence i am okay with it.
Yeah so I open to work ... just PM me.
And please don't try to scan big websites like Amazon or any other related your ip will be blacklisted.
Tetstack
Better...
Literally got the idea from jem stones I found in the living room
I am not a social type of guy but I love joining public groups to collect unique stickers, won't use them but they joining my pack.
Tetstack
I need some money so I will start selling advanced version of the KASCVE tool known as KASCVE-BUG for specifically bug-bounty. If any one want to buy my tool it's for sale just PM me
I will explain later why but how do I block my dad on linkedin
So coming back to the point the deference bn KASCVE and KASCVE-BUG is KESCVE-BUG can test real world enterprise big website like Amazon or any other with out getting your ip blocked by the firewall cuz of high traffic, give full analysis on which CVE is where.
Public Version (Baseline)
Single-Target Auditing – Requires manual execution against one endpoint or asset at a time.
Passive Surface Mapping – Collects raw configuration data, server headers, and basic asset footprints.
Raw Data Assessment – Provides a standard list of findings that require manual triage and analysis.
Vulnerability Reporting – Identifies the issue but leaves the remediation strategy entirely up to the user.
Standalone Script – Runs locally and requires manual environment configuration and active monitoring.
Premium Version (Upgraded)
Multi-Target Campaigns – Automates wide-scope discovery across massive, bulk target lists simultaneously.
Active Flaw Verification – Probes deeper using structural HTML form analysis and integrated fuzzing to expose high-impact vulnerabilities like missing Anti-CSRF tokens and SQLi entry points.
Prioritized Severity Matrix – Automatically categorizes risks by threat level so you instantly know what to fix first.
Production Remediation Blueprints – Delivers drop-in config fixes tailored specifically for deployment environments like Nginx, Apache, and Laravel.
Global CLI Utility – Features an automated system installer, seamless environment setup, and built-in rate-limiting logic for safe, reliable scanning.