cve
Tracked open-source repos tagged cve, sorted by stars.
Related topics
Topics that frequently appear alongside cve on the same repo.
Recent risers
Repos created in the last 90 days, tagged cve.
- #1
Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.
★ 1,377 - #2
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
★ 914 - #3
A cPanel and WHM authentication bypassing tool
★ 531 - #4
CVE-2026-9830 Proof of Concept
★ 399 - #5
A cPanel and WHM authentication bypassing tool
★ 283
- #1
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
★ 22,465+53Star change over the last 7 days - #2
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
★ 11,103+38Star change over the last 7 days - #3★ 8,030+11Star change over the last 7 days
- #4
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
★ 8,027+27Star change over the last 7 days - #5
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
★ 7,477+12Star change over the last 7 days - #6★ 6,698+7Star change over the last 7 days
- #7
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
★ 5,542+20Star change over the last 7 days - #8
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
★ 4,076+6Star change over the last 7 days - #9
Nmap NSE scripts that turn a service scan into CVEs, CVSS scores and known exploits — fingerprints software from HTTP responses and checks every detected CPE against the Vulners database.
★ 3,416+9Star change over the last 7 days - #10★ 3,309+27Star change over the last 7 days
- #11★ 2,811+2Star change over the last 7 days
- #12
cve-search - a tool to perform local searches for known vulnerabilities
★ 2,642+3Star change over the last 7 days - #13
A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
★ 2,481+0Star change over the last 7 days - #14
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
★ 2,457+0Star change over the last 7 days - #15★ 2,235+1Star change over the last 7 days
- #16
一个基于 docsify 快速部署 Awesome-POC 漏洞文档的项目。Deploying the Awesome-POC repository via docsify.
★ 2,177+6Star change over the last 7 days - #17
Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.
★ 1,814+3Star change over the last 7 days - #18
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
★ 1,753+6Star change over the last 7 days - #19★ 1,516-1Star change over the last 7 days
- #20★ 1,464+2Star change over the last 7 days
- #21
Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.
★ 1,377+75Star change over the last 7 days - #22
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
★ 1,290+85Star change over the last 7 days - #23
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
★ 1,281+2Star change over the last 7 days - #24
80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
★ 1,276+3Star change over the last 7 days - #25
Automatically Collect POC or EXP from GitHub by CVE ID.
★ 1,197+4Star change over the last 7 days - #26★ 1,129+1Star change over the last 7 days
- #27★ 914+2Star change over the last 7 days
- #28
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
★ 914+0Star change over the last 7 days - #29★ 906+1Star change over the last 7 days
- #30
Guidance for the Spectre, Meltdown, Speculative Store Bypass, Rogue System Register Read, Lazy FP State Restore, Bounds Check Bypass Store, TLBleed, and L1TF/Foreshadow vulnerabilities as well as general hardware and firmware security guidance. #nsacyber
★ 875+0Star change over the last 7 days