vulnerabilities
Tracked open-source repos tagged vulnerabilities, sorted by stars.
- #31
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
★ 1,756+3Star change over the last 7 days - #32★ 1,704+1Star change over the last 7 days
- #33
Metarget is a framework providing automatic constructions of vulnerable infrastructures.
★ 1,415+0Star change over the last 7 days - #34
A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.
★ 1,389+3Star change over the last 7 days - #35
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
★ 1,333+0Star change over the last 7 days - #36
Collection of npm package manager Security Best Practices
★ 1,250+1Star change over the last 7 days - #37
Automatically Collect POC or EXP from GitHub by CVE ID.
★ 1,198+2Star change over the last 7 days - #38
Security advisory database for Rust crates published through crates.io
★ 1,171+3Star change over the last 7 days - #39
Very vulnerable ARM/AARCH64 application (CTF style exploitation tutorial with 29 vulnerability techniques)
★ 1,110+3Star change over the last 7 days - #40
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
★ 1,109+3Star change over the last 7 days - #41
Repository for information about 0-days exploited in-the-wild.
★ 1,039+0Star change over the last 7 days - #42★ 923+1Star change over the last 7 days
- #43★ 860+0Star change over the last 7 days
- #44
Zip Slip Vulnerability (Arbitrary file write through archive extraction)
★ 855+1Star change over the last 7 days - #45★ 843+5Star change over the last 7 days
- #46
Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.
★ 748+0Star change over the last 7 days - #47★ 747+0Star change over the last 7 days
- #48
scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。
★ 736+1Star change over the last 7 days - #49
An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.
★ 729+1Star change over the last 7 days - #50
Integrates Dependency-Check reports into SonarQube
★ 694+1Star change over the last 7 days - #51
PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
★ 638+0Star change over the last 7 days - #52
A Collection of Vulnerabilities in ERC20 Smart Contracts With Tokens Affected
★ 629-2Star change over the last 7 days - #53★ 618+1Star change over the last 7 days
- #54★ 595+0Star change over the last 7 days
- #55
VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/DOCX, attachments, automatic changelog, stats, vulnerability management, bugbounty, local ai/llm, super fast pentest reporting!
★ 577+1Star change over the last 7 days - #56
Bugcrowd’s baseline priority ratings for common security vulnerabilities
★ 558+2Star change over the last 7 days - #57
ClusterFuzzLite - Simple continuous fuzzing that runs in CI.
★ 535+0Star change over the last 7 days - #58★ 526+2Star change over the last 7 days
- #59★ 525+0Star change over the last 7 days