OWASP ZAP - A widely-used dynamic application security testing (DAST) tool for finding vulnerabilities in web applications during runtime. https://www.zaproxy.org