Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

https://github.com/interference-security/DVWS

OWSAP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application which works on web sockets for client-server communication.

mysql owasp php ratchet vulnerabilities websockets

Last synced: 29 Jun 2024

https://github.com/intel/cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

cve cvss devsecops hacktoberfest python sbom sbom-tool security security-automation security-tools swrepo system-tools vulnerabilities vulnerability

Last synced: 26 Jun 2024

https://github.com/Jorijn/laravel-security-checker

Added Laravel functionality to Enlightn Security Checker. Adds a command to check for, and optionally emails you, vulnerabilities when they affect you.

laravel laravel-package laravel-security-checker php sensiolabs-security-checker vulnerabilities

Last synced: 25 Jun 2024

https://google.github.io/clusterfuzzlite/

ClusterFuzzLite - Simple continuous fuzzing that runs in CI.

ci continuous-integration fuzz-testing fuzzing security vulnerabilities

Last synced: 22 Jun 2024

https://github.com/deadbits/InsecureProgramming

mirror of gera's insecure programming examples | http://community.coresecurity.com/~gera/InsecureProgramming/

c exploitation learning-exercise security security-vulnerability vulnerabilities

Last synced: 17 Jun 2024

https://github.com/ForceFledgling/CVE-2023-22518

Improper Authorization Vulnerability in Confluence Data Center and Server + bonus 🔥

atlassian atlassian-confluence attack backdoor confluence critical cve exploit exploiting hacking hacking-tool improper python shell vulnerabilities vulnerability

Last synced: 17 Jun 2024

https://github.com/ant4g0nist/Vulnerable-Kext

A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation

driver exploit-development exploitation ios kernel macos memory-corruption vulnerabilities xnu

Last synced: 15 Jun 2024

https://github.com/jaeles-project/jaeles

The Swiss Army knife for automated Web Application Testing

bugbounty golang hacking infosec jaeles scanner security-tools vulnerabilities web-scanner

Last synced: 14 Jun 2024

https://github.com/jcsec-security/solidity-security-course-resources

Course material about common vulnerabilities, security and audits of Solidity smart contracts that I use during my lectures

audit beginner bug bugbounty contract ethereum evm security smart smart-contracts smartcontract solidity vulnerabilities

Last synced: 13 Jun 2024

https://github.com/Medicean/VulApps

快速搭建各种漏洞环境(Various vulnerability environment)

cve docker struts vulnerabilities vulnhub

Last synced: 11 Jun 2024

https://github.com/MystenLabs/ed25519-unsafe-libs

List of unsafe ed25519 signature libs

attacks blockchain cryptography ed25519 vulnerabilities

Last synced: 11 Jun 2024

https://github.com/google/clusterfuzz

Scalable fuzzing infrastructure.

fuzzing security stability vulnerabilities

Last synced: 11 Jun 2024

https://github.com/yqcs/heartsk_community

Hearts K-企业资产发现与脆弱性检查工具,自动化资产信息收集与漏洞扫描

heartsk poc vulnerabilities vulnerability-scanners

Last synced: 06 Jun 2024

https://github.com/pedrib/PoC

Advisories, proof of concept files and exploits that have been made public by @pedrib.

advisories exploits hacking metasploit vulnerabilities

Last synced: 05 Jun 2024

https://github.com/bugcrowd/vulnerability-rating-taxonomy

Bugcrowd’s baseline priority ratings for common security vulnerabilities

bugcrowd rating taxonomy vrt vulnerabilities

Last synced: 05 Jun 2024

https://github.com/ycdxsb/PocOrExp_in_Github

聚合Github上已有的Poc或者Exp,CVE信息来自CVE官网。Auto Collect Poc Or Exp from Github by CVE ID.

cve exploit poc vulnerabilities

Last synced: 05 Jun 2024

https://github.com/dirsoooo/Recon

Recon is a script to perform a full recon on a target with the main tools to search for vulnerabilities. Created based on @ofjaaah and @Jhaddix methodologies

dorks methodologies pentest recon vulnerabilities xss

Last synced: 05 Jun 2024

https://github.com/Retr0-code/SignHere

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.

automation build-tool builder cve cve-2017-11882 equation malicious microsoft office python3 rtf vulnerabilities

Last synced: 05 Jun 2024

https://github.com/ochronasec/ochrona-cli

A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installs

dependency-analysis developer-tools devsecops pip pipfile python requirements security security-tools supply-chain vulnerabilities vulnerability-scanners

Last synced: 05 Jun 2024

https://github.com/righel/ms-exchange-version-nse

Nmap script to detect a Microsoft Exchange instance version with OWA enabled.

cve cve-scanning microsoft-exchange nmap nmap-script nse proxyshell vulnerabilities

Last synced: 05 Jun 2024

https://github.com/harsh-bothra/learn365

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

application-security bugbounty bugbountytips community infosec learning pentesting pentesting-tools vulnerabilities

Last synced: 05 Jun 2024

https://github.com/mirego/elixir-security-advisories

🛡 Public database of Elixir security advisories pulled from GitHub Advisory Database

advisories elixir erlang security vulnerabilities

Last synced: 05 Jun 2024

https://github.com/BeetleChunks/SpoolSploit

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

container cve-2021-1675 cve-2021-34527 docker exploit print printspooler python rpc scanner spool vulnerabilities windows

Last synced: 02 Jun 2024

https://github.com/archerysec/archerysec

Automate Your Application Security Orchestration And Correlation (ASOC) Using ArcherySec.

devops devops-tools devsecops opensource pentesters pentesting scanning secdevops vulnerabilities vulnerability-assessment vulnerability-management

Last synced: 02 Jun 2024

https://github.com/six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

bug-bounty bugbounty dns fuzzing hacking nuclei osint penetration-testing pentest pentest-tool pentesting recon reconnaissance scanner security security-tools subdomain vulnerabilities

Last synced: 02 Jun 2024

https://github.com/01rabbit/PAKURI

PAKURI has been merged with Python and launched as a new project, PAKURI-THON.

arsenal exploitation faraday kali metasploit openvas penetration-testing pentest-tool pentesting-tools scanning vulnerabilities

Last synced: 30 May 2024

https://github.com/RustSec/advisory-db

Security advisory database for Rust crates published through crates.io

rust security security-advisories security-audit vulnerabilities

Last synced: 30 May 2024

https://github.com/docker/scan-cli-plugin

Docker Scan is a Command Line Interface to run vulnerability detection on your Dockerfiles and Docker images

docker docker-container docker-image dockerfile vulnerabilities vulnerability vulnerability-detection vulnerability-scanners

Last synced: 30 May 2024

https://github.com/ZupIT/horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

analysis cd ci cli golang hacktoberfest java kotlin netcore python ruby sast sast-analysis scanner security security-development security-flaws static-analysis terraform vulnerabilities

Last synced: 30 May 2024

https://github.com/XmirrorSecurity/OpenSCA-cli

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

cyclonedx devsecops license-compliance sbom sca security software-bill-of-materials software-composition-analysis software-supply-chain software-supply-chain-security spdx static-analysis swid vulnerabilities

Last synced: 30 May 2024

https://github.com/DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

appsec bill-of-materials bom component-analysis cyclonedx devsecops nvd ossindex owasp package-url purl sbom sca security security-automation software-composition-analysis software-security vulndb vulnerabilities vulnerability-detection

Last synced: 30 May 2024

https://github.com/avishayil/python-snyk-test

A tool that wraps pysnyk library for easier usage from command line interfaces

oss pypi python snyk test vulnerabilities

Last synced: 27 May 2024

https://github.com/snyk-tech-services/snyk-licenses-texts

📑 Snyk API powered licenses attribution report tool. Generate licenses information per Snyk Organization with license name, text, dependencies data and copyright information

html-report json snyk snyk-tooling vulnerabilities

Last synced: 27 May 2024

https://github.com/asos/snyker

An opinionated, heavy-handed wrapper around Snyk.

cli security snyk snyk-cli vulnerabilities vulnerable-paths

Last synced: 27 May 2024

https://github.com/lirantal/npq

🎖safely* install packages with npm or yarn by auditing them as part of your install process

command-line-tool hacktoberfest npm package-manager security security-audit security-tools vulnerabilities

Last synced: 26 May 2024

https://github.com/go-outside-labs/sec-pentesting-toolkit

👾 𝘁𝗼𝗼𝗹𝘀 𝗳𝗼𝗿 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵𝗲𝗿𝘀: 𝗽𝗲𝗻𝘁𝗲𝘀𝘁𝗶𝗻𝗴, 𝗖𝗧𝗙𝘀 & 𝘄𝗮𝗿𝗴𝗮𝗺𝗲𝘀

botnets cryptography ctf forensics gray-hacker-resources hacking infosec iocs linux malwares network penetration-testing pentesting post-exploitation reverse-engineering rubber-ducky steganography vulnerabilities wargame web-security

Last synced: 25 May 2024

https://github.com/sec-bit/awesome-buggy-erc20-tokens

A Collection of Vulnerabilities in ERC20 Smart Contracts With Tokens Affected

awesome awesome-list dapp erc20 erc20-tokens ethereum security smart-contracts solidity tokens vulnerabilities

Last synced: 25 May 2024

https://github.com/patois/drgadget

dr.rer.oec.gadget IDAPython plugin for the Interactive Disassembler <ABANDONED PROJECT>

exploitation ida-plugin ida-pro idapython idapython-plugin python rop rop-analysis rop-chain rop-gadgets vulnerabilities

Last synced: 24 May 2024

https://github.com/snyk/serverless-snyk

Serverless plugin for securing your dependencies with Snyk

security serverless snyk vulnerabilities

Last synced: 21 May 2024

https://github.com/snyk/zip-slip-vulnerability

Zip Slip Vulnerability (Arbitrary file write through archive extraction)

security vulnerabilities

Last synced: 21 May 2024

https://github.com/BugScanTeam/GitHack

.git 泄漏利用工具,可还原历史版本

git vulnerabilities

Last synced: 19 May 2024

https://github.com/StarCrossPortal/scalpel

scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。

cve exploits fuzzing poc scanner vulnerabilities vulnerability

Last synced: 19 May 2024

https://github.com/pwnedshell/Bugs-feed

Bug's feed is a local hosted portal where you can search for the latest news, videos, CVEs, vulnerabilities...

bugbounty cve hacking python scrapping vulnerabilities

Last synced: 19 May 2024

https://github.com/yallxe/hogg

Common vulnerability scanning on steroids ☄️

dns exploit network proxy rust rust-lang scanner secrets security sniffer vulnerabilities webscanner

Last synced: 16 May 2024

https://github.com/PayDevs/awful-oss-incidents

🤬 A categorized list of incidents caused by unappreciated OSS maintainers or underfunded OSS projects. Feedback welcome!

fuck-ups incidents npmjs open-source oss vulnerabilities

Last synced: 15 May 2024

https://github.com/spencerdodd/kernelpop

kernel privilege escalation enumeration and exploitation framework

enumeration exploits kernel security tools vulnerabilities

Last synced: 14 May 2024

https://github.com/HackOvert/awesome-bugs

A collection of software bug types and articles showcasing the hunt for and exploitation of them.

awesome-list software-bug vulnerabilities

Last synced: 14 May 2024

https://github.com/R0X4R/Pinaak

A vulnerability fuzzing tool written in bash, it contains the most commonly used tools to perform vulnerability scan

bash-script bugbounty fastscanner find-vulnerabilities nuclei sqlinjection vulnerabilities vulnerability-scanners xss-vulnerability

Last synced: 14 May 2024

https://github.com/tintinweb/smart-contract-vulndb

🍋 An open dataset containing smart contract audit issues from various sources.

smart-contract-security vulnerabilities

Last synced: 12 May 2024

https://github.com/CERTCC/PoC-Exploits

Select proof-of-concept exploits for software vulnerabilities to aid in identifying and testing vulnerable systems.

exploits poc vulnerabilities

Last synced: 12 May 2024

https://github.com/jgamblin/CPEData

NVD CPE Data

cpe cve nvd vulnerabilities

Last synced: 12 May 2024

https://github.com/ethicalhackingplayground/tprox

TProx is a fast reverse proxy path traversal detector and directory bruteforcer.

hacking misconfigurations pentesting proxy vulnerabilities

Last synced: 12 May 2024

https://github.com/edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

awesome awesome-list awesome-lists bugbounty cve dns exploit hacking hacking-tools hacktoberfest osint osint-tool redteam redteaming search-engine security security-tools vulnerabilities vulnerability wifi-network

Last synced: 09 May 2024

https://github.com/FriendsOfPHP/security-advisories

A database of PHP security advisories

composer packagist php vulnerabilities

Last synced: 09 May 2024

https://github.com/aquasecurity/kube-hunter

Hunt for security weaknesses in Kubernetes clusters

hacktoberfest kubernetes-clusters vulnerabilities

Last synced: 09 May 2024

https://github.com/fosslight/fosslight

FOSSLight Hub : Integrated management web-service for Open Source Compliance Process

license management open-source spring-boot supply-chain vulnerabilities

Last synced: 09 May 2024

https://google.github.io/oss-fuzz/

OSS-Fuzz - continuous fuzzing for open source software.

fuzz-testing fuzzing oss-fuzz security stability vulnerabilities

Last synced: 09 May 2024

https://github.com/trailofbits/cb-multios

DARPA Challenges Sets for Linux, Windows, and macOS

decree test-suite vulnerabilities

Last synced: 08 May 2024

https://github.com/snyk/cli

Snyk CLI scans and monitors your projects for security vulnerabilities.

monitor security snyk vulnerabilities

Last synced: 07 May 2024

https://github.com/quay/clair

Vulnerability Static Analysis for Containers

clair containers docker go kubernetes oci oci-image static-analysis vulnerabilities

Last synced: 07 May 2024

https://github.com/anchore/anchore-engine

A service that analyzes docker images and scans for vulnerabilities

anchore-engine containers docker docker-image dockerhub python security static-analysis vulnerabilities whitelist

Last synced: 07 May 2024

https://github.com/google/clusterfuzzlite

ClusterFuzzLite - Simple continuous fuzzing that runs in CI.

ci continuous-integration fuzz-testing fuzzing security vulnerabilities

Last synced: 04 May 2024

https://github.com/NeuraLegion/sslscan.cr

Crystal shard wrapping the rbsec/sslscan utility

crystal detection scanner security shard ssl tls vulnerabilities

Last synced: 02 May 2024

https://github.com/sonatype-nexus-community/scan-gradle-plugin

Gradle plugin that scans the dependencies of a Gradle project using Sonatype platforms: OSS Index and Nexus IQ Server.

audit dependencies evaluate gradle gradle-plugin iq-server scan sonatype vulnerabilities

Last synced: 01 May 2024

https://github.com/presidentbeef/brakeman

A static analysis security vulnerability scanner for Ruby on Rails applications

brakeman rails ruby security security-audit security-tools security-vulnerability static-analysis vulnerabilities

Last synced: 01 May 2024