vulnerability
Tracked open-source repos tagged vulnerability, sorted by stars.
- #61
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
★ 806+1Star change over the last 7 days - #62
Recent CVE PoC & reproduction scripts. Focused on high-severity vulnerabilities across Linux kernel, Windows, macOS and more.
★ 794+10Star change over the last 7 days - #63
A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner
★ 782+2Star change over the last 7 days - #64
scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。
★ 736+1Star change over the last 7 days - #65★ 733+2Star change over the last 7 days
- #66
An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.
★ 729+2Star change over the last 7 days - #67
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
★ 702+3Star change over the last 7 days - #68
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
★ 692+1Star change over the last 7 days - #69
Nacos 综合漏洞利用工具
★ 688+2Star change over the last 7 days - #70
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
★ 688+7Star change over the last 7 days - #71★ 685+2Star change over the last 7 days
- #72
Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.
★ 662+0Star change over the last 7 days - #73
汽车/安卓/固件/代码安全测试工具集
★ 655+1Star change over the last 7 days - #74★ 633-3Star change over the last 7 days
- #75
Modern image vulnerability scanning & patching platform with multi-tool integration.
★ 626+0Star change over the last 7 days - #76
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
★ 617+3Star change over the last 7 days - #77
Jie stands out as a comprehensive security assessment and exploitation tool meticulously crafted for web applications. Its robust suite of features encompasses vulnerability scanning, information gathering, and exploitation, elevating it to an indispensable toolkit for both security professionals and penetration testers. 挖洞辅助工具(漏洞扫描、信息收集)
★ 608-1Star change over the last 7 days - #78★ 606+7Star change over the last 7 days
- #79
Awesome Writeups and POCs
★ 572+0Star change over the last 7 days - #80
Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
★ 530+1Star change over the last 7 days - #81★ 525+0Star change over the last 7 days
- #82
CVE-2026-9830 Proof of Concept
★ 516+146Star change over the last 7 days