#vulnerabilities (21 Repositories)
Ranked open-source repositories tagged with #vulnerabilities, scored by pull request acceptance likelihood and maintainer engagement velocity.
26.4%
32.4h
21 repositories tagged #vulnerabilities
phylum-dev/cli
Command line interface for the Phylum API
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
seqra/opentaint
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
FriendsOfPHP/security-advisories
A database of PHP security advisories
fosslight/fosslight
FOSSLight Hub : Integrated management web-service for Open Source Compliance Process
google/oss-fuzz
OSS-Fuzz - continuous fuzzing for open source software.
RetireJS/retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
eraser-dev/eraser
🧹 Cleaning up images from Kubernetes nodes
trickest/cve
Gather and update all available and newest CVEs with their PoC.
anchore/scan-action
Anchore container analysis and scan provided as a GitHub Action
ycdxsb/PocOrExp_in_Github
Automatically Collect POC or EXP from GitHub by CVE ID.
mirego/elixir-security-advisories
🛡 Public database of Elixir security advisories pulled from GitHub Advisory Database
bugcrowd/vulnerability-rating-taxonomy
Bugcrowd’s baseline priority ratings for common security vulnerabilities
sandworm-hq/sandworm-audit
Security & License Compliance For Your App's Dependencies 🪱
swisskyrepo/Vulny-Code-Static-Analysis
Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex
x1337loser/Dependency-Confusion
All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)
albuch/sbt-dependency-check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). :rainbow:
YalcinYolalan/WSSAT
WEB SERVICE SECURITY ASSESSMENT TOOL
ossf/cve-bin-tool
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
monarc-project/MonarcAppFO
MONARC - Method for an Optimised aNAlysis of Risks by @NC3-LU
six2dez/reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities