Skip to main content
buildradar
Sign in
Topic · vulnerability

vulnerability

Tracked open-source repos tagged vulnerability, sorted by stars.

82 repos
  • RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

    1,932-1Star change over the last 7 days
  • watchvuln@zema1

    一个高价值漏洞采集与推送服务 | Collect valueable vulnerabilities and push them to various services

    1,890+5Star change over the last 7 days
  • BlackWidow@1N3

    A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

    1,820-1Star change over the last 7 days
  • getsploit@vulnersCom

    Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

    1,815+1Star change over the last 7 days
  • cve-bin-tool@ossf

    The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

    1,756+3Star change over the last 7 days
  • appshark@bytedance

    Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

    1,753+0Star change over the last 7 days
  • Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

    1,708+3Star change over the last 7 days
  • copacetic@project-copacetic

    🧵 CLI tool for directly patching container images!

    1,704+1Star change over the last 7 days
  • guac@guacsec

    GUAC aggregates software security metadata into a high fidelity graph database.

    1,537+3Star change over the last 7 days
  • HummerRisk@HummerRisk

    HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

    1,512+0Star change over the last 7 days
  • Burp Suite Certified Practitioner Exam Study

    1,465+2Star change over the last 7 days
  • trivy-action@aquasecurity

    Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

    1,408+1Star change over the last 7 days
  • pocindex@0xMarcio

    Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.

    1,378+8Star change over the last 7 days
  • singularity@nccgroup

    A DNS rebinding attack framework.

    1,316+1Star change over the last 7 days
  • secator@freelabz

    secator - the pentester's swiss knife

    1,306-1Star change over the last 7 days
  • nuclei-wordfence-cve@topscoder

    80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

    1,278+0Star change over the last 7 days
  • hack-tools@hacktoolspack

    hack tools

    1,219+1Star change over the last 7 days
  • Bad-Pdf@deepzec

    Steal Net-NTLM Hash using Bad-PDF

    1,151+0Star change over the last 7 days
  • This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation".

    996+0Star change over the last 7 days
  • secDevLabs@globocom

    A laboratory for learning secure web and mobile development in a practical manner.

    980+1Star change over the last 7 days
  • reconmap@reconmap

    Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.

    975+0Star change over the last 7 days
  • oFx@bigblackhat

    一个开源的、开箱即用的漏洞批量验证框架

    916+2Star change over the last 7 days
  • These are my checklists which I use during my hunting.

    894+2Star change over the last 7 days
  • Guidance for the Spectre, Meltdown, Speculative Store Bypass, Rogue System Register Read, Lazy FP State Restore, Bounds Check Bypass Store, TLBleed, and L1TF/Foreshadow vulnerabilities as well as general hardware and firmware security guidance. #nsacyber

    876+1Star change over the last 7 days
  • vulnix@nix-community

    Vulnerability (CVE) scanner for Nix/NixOS [maintainer=@henrirosten]

    846+6Star change over the last 7 days
  • prismx@yqcs

    :: Prism X · Automated Enterprise Network Security Risk Detection and Vulnerability Scanning Tool / 棱镜 X · 自动化企业网络安全风险检测、漏洞扫描工具

    837+1Star change over the last 7 days
  • PoC@thezdi

    Proofs-of-concept

    833+1Star change over the last 7 days
  • sicat@justakazh

    The useful exploit finder

    830+2Star change over the last 7 days
  • CVE-2026-24061@jacubes

    CVE-2026-24061 exploit PoC

    824+0Star change over the last 7 days
  • Garud@R0X4R

    An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

    811+0Star change over the last 7 days
← Back to topics