#vulnerability (30 Repositories)
Ranked open-source repositories tagged with #vulnerability, scored by pull request acceptance likelihood and maintainer engagement velocity.
33.3%
148.3h
30 repositories tagged #vulnerability
greenbone/gvmd
Greenbone Vulnerability Manager - The database backend for the Greenbone Community Edition
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
google/osv.dev
Open source vulnerability DB and triage service.
greenbone/gsa
Greenbone Security Assistant - The web frontend for the Greenbone Community Edition
greenbone/openvas-scanner
This repository contains the scanner component for Greenbone Community Edition.
digitalcoyote/NuGetDefense
An MSBuildTask that checks for known vulnerabilities. Inspired by OWASP SafeNuGet.
Tencent/AI-Infra-Guard
A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
anchore/grype
A vulnerability scanner for container images and filesystems
Unclecheng-li/cybersecurity-daily
网络安全日报—每日推送;Daily updated report on cybersecurity hotspots
project-copacetic/copacetic
🧵 CLI tool for directly patching container images!
aquasecurity/trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
jar-analyzer/jar-analyzer
Jar Analyzer - 一个 JAR 包 GUI 分析工具,内置 AI 助手协助分析,支持 JAR DIFF 分析,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索等
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
reconmap/reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
jacubes/CVE-2026-24061
CVE-2026-24061 exploit PoC
trickest/cve
Gather and update all available and newest CVEs with their PoC.
aboutcode-org/vulnerablecode
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
makenowjust-labs/recheck
The trustworthy ReDoS checker
aquasecurity/trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
The-Art-of-Hacking/h4cker
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study
Burp Suite Certified Practitioner Exam Study
sandworm-hq/sandworm-audit
Security & License Compliance For Your App's Dependencies 🪱
Exploit-Garbage/0day-Rubbish
Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field.
Fuzzapi/API-fuzzer
API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities
chennqqi/godnslog
An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability
frohoff/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
warpnet/MS-RPC-Fuzzer
Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopefully identify interesting RPC services in such a time that would take a manual approach significantly more.
dzonerzy/goWAPT
Go Web Application Penetration Test
infobyte/faraday
Open Source Vulnerability Management Platform
AabyssZG/HashDump-BypassEDR
Windows绕过EDR实现DumpHash