Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Projects in Awesome Lists tagged with vulnerabilities

A curated list of projects in awesome lists tagged with vulnerabilities .

https://github.com/nekmo/pip-rating

Check the health of your project's requirements and get a score for each dependency.

dependencies hacktoberfest pip python rating requirements security security-audit security-tools vulnerabilities

Last synced: 09 Nov 2024

https://github.com/ethicalhackingplayground/tprox

TProx is a fast reverse proxy path traversal detector and directory bruteforcer.

hacking misconfigurations pentesting proxy vulnerabilities

Last synced: 08 Nov 2024

https://github.com/devmatic-it/debcvescan

Debian CVE Scanner is self-contained CVE scanner for DEBIAN distributions written in golang.

cve debian go golang security-scanner vulnerabilities

Last synced: 15 Nov 2024

https://github.com/openclarity/kubeclarity

KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems

kubernetes kubernetes-security sbom scanner security supply-chain vulnerabilities

Last synced: 15 Oct 2024

https://github.com/vacuumlabs/cardano-ctf

A game where Cardano developers and enthusiasts can try to exploit purposely vulnerable smart contracts and learn about the most common security issues and how to prevent them.

cardano ctf decentralized-finance security smart-contracts vulnerabilities

Last synced: 07 Nov 2024

https://github.com/volkansah/gpt-security-best-practices

The purpose of this document is to outline the security risks and vulnerabilities that may arise when implementing ChatGPT in web applications and to provide best practices for mitigating these risks.

ajax ajax-request chatgpt chf code-security html js php security security-risks server-side serverside-rendering vulnerabilities vulnerabilities-fix

Last synced: 09 Dec 2024

https://github.com/VolkanSah/GPT-Security-Best-Practices

The purpose of this document is to outline the security risks and vulnerabilities that may arise when implementing ChatGPT in web applications and to provide best practices for mitigating these risks.

ajax ajax-request chatgpt chf code-security html js php security security-risks server-side serverside-rendering vulnerabilities vulnerabilities-fix

Last synced: 18 Nov 2024

https://github.com/Orange-OpenSource/floss-toolbox

A toolbox to help developers and open source referents to not waste their time with manual and boring tasks. Provides simple and light tools to make investigations in source code to look for hot data. Provides also primitives to manage GitHub and GitLab organizations.

admin bash commits dco dependabot github gitlab gitleaks hacktoberfest hacktoberfest2024 hotwords logs octokit osint ruby shell signed-off toolbox vulnerabilities

Last synced: 14 Dec 2024

https://github.com/jishanshaikh4/jaam

Web Browser Security Framework

jaam security security-tools vulnerabilities web-browser

Last synced: 10 Nov 2024

https://github.com/bugscanteam/bugrequest

Sniffer vulnerabilities in http request (chrome extension)

chrome-extension jsonp redirect-urls vulnerabilities

Last synced: 20 Nov 2024

https://github.com/caverav/auditforge

AuditForge is a pentest reporting application making it simple and easy to write your findings and generate a customizable report.

audit cybersecurity infosec penetration-testing pentesting pentesting-tools reporting reporting-tool security security-tools vulnerabilities

Last synced: 22 Nov 2024

https://github.com/justakazh/CVE_Database

The Common Vulnerabilities Exposures (CVE) Database

0day cve cwe database infosec json nvd pentester security vulnerabilities vulnerability zeroday

Last synced: 18 Jan 2025

https://github.com/aboutcode-org/dejacode

Automate open source license compliance and ensure software supply chain integrity

cyclonedx foss-compliance license open-source package-url purl sca scancode spdx vulnerabilities

Last synced: 14 Nov 2024

https://github.com/yallxe/hogg

Common vulnerability scanning on steroids ☄️

dns exploit network proxy rust rust-lang scanner secrets security sniffer vulnerabilities webscanner

Last synced: 26 Nov 2024

https://github.com/qeeqbox/cyber-attacks

A collection of attacks metadata that were used in my previous pen-test tools

attacks cyber vulnerabilities

Last synced: 16 Jan 2025

https://github.com/sec4you/vulnlabs

docker-compose bringing up multiple vulnerable applications inside containers.

docker docker-compose vulnerabilities vulnerable vulnerable-application vulnerable-container vulnerable-web-app

Last synced: 13 Nov 2024

https://github.com/securestackco/actions-log4j

A GitHub Action that scans your public web applications for log4j vulnerabilities after every deployment. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements.

devsecops github-actions java java-vulnerability java8 jre log4j log4j-rce log4j2 log4js log4shell scanning security security-automation security-tools software-composition-analysis static-analysis vulnerabilities vulnerability-assessment vulnerability-scanner

Last synced: 04 Dec 2024

https://github.com/lambdacasserole/hack-this

A collection of common web programming security mistakes.

education hacking php security sql-injection vulnerabilities

Last synced: 06 Jan 2025

https://github.com/maikuolan/vulnerability-charts

Some simple charts for listing CVSS by version for various packages.

charts cve cvss hhvm php phpmyadmin python vulnerabilities vulnerability

Last synced: 28 Oct 2024

https://github.com/rasoolsomji/django-security

Django is great! Here are some ways to make it safer

audit csrf cybersecurity django nginx owasp pentest python security vulnerabilities xss

Last synced: 25 Oct 2024

https://github.com/demining/twist-attack

In this article, we will implement a Twist Attack with an example and show how, using certain points on the secp256k1 elliptic curve, we can get partial private key values ​​and restore a Bitcoin Wallet within 5-15 minutes using “Sagemath pollard rho function: (discrete_log_rho)” and “ Chinese Remainder Theorem” .

attack attacker bitcoin bitcoin-wallet blockchain blockchain-technology cryptocurrency exploit exploiting exploiting-vulnerabilities hack hacking vulnerabilities vulnerability vulnerability-scanners

Last synced: 11 Jan 2025

https://github.com/machine1337/open-redirector

A small and efficient tool to find open redirect vulnerabilities.

bugbounty hacking machine1337 openredirect-scanner vulnerabilities

Last synced: 10 Nov 2024

https://github.com/snyk-tech-services/snyk-licenses-texts

📑 Snyk API powered licenses attribution report tool. Generate licenses information per Snyk Organization with license name, text, dependencies data and copyright information

html-report json snyk snyk-tooling vulnerabilities

Last synced: 19 Nov 2024

https://github.com/paulveillard/cybersecurity-blue-team

A collection of awesome software, libraries, learning tutorials, documents and books, technical resources and cool stuff about Blue Team in Cybersecurity.

blue blue-team cyber-threat-intelligence cybernetics cybersecurity vulnerabilities vulnerability-identification vulnerability-management vulnerability-research vulnerability-scanners vulnerability-scanning

Last synced: 07 Dec 2024

https://github.com/anthonyharrison/lib4vex

Library to ingest and generate VEX documents

csaf cyclonedx devsecops library openvex python sbom vex vulnerabilities

Last synced: 07 Nov 2024

https://github.com/demining/twist-attack-2

In this article, we will implement a Twist Attack with an example and show how, using certain points on the secp256k1 elliptic curve, we can get partial private key values ​​and restore a Bitcoin Wallet within 5-15 minutes using “Sagemath pollard rho function: (discrete_log_rho)” and “ Chinese Remainder Theorem” .

attack attacker bitcoin bitcoin-wallet blockchain blockchain-technology cryptocurrency exploit exploiting exploiting-vulnerabilities hack hacking vulnerabilities vulnerability vulnerability-scanners

Last synced: 11 Jan 2025

https://github.com/anchore/vulnerability-match-labels

Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners

dataset hacktoberfest labels vulnerabilities

Last synced: 10 Nov 2024

https://github.com/NeuraLegion/sslscan.cr

Crystal shard wrapping the rbsec/sslscan utility

crystal detection scanner security shard ssl tls vulnerabilities

Last synced: 18 Nov 2024

https://github.com/markwhitaker/vulnerable-site

A deliberately vulnerable website used to showcase Dastardly from Burp Suite

vulnerabilities vulnerability-detection website

Last synced: 16 Jan 2025

https://github.com/neuralegion/sslscan.cr

Crystal shard wrapping the rbsec/sslscan utility

crystal detection scanner security shard ssl tls vulnerabilities

Last synced: 19 Nov 2024

https://github.com/jdgregson/disclosures

My publically disclosed vulnerability reports.

exploit exploits poc vulnerabilities vulnerability

Last synced: 19 Dec 2024

https://github.com/phylum-dev/vuln-reach

A library for building tools to determine if vulnerabilities are reachable in a code base.

cve security vulnerabilities

Last synced: 19 Nov 2024

https://github.com/twlinux/lets-talk

Intentionally vulnerable website that demonstrates beginner-level injection vulnerabilities

sqli vulnerabilities xss

Last synced: 18 Nov 2024

https://github.com/dreadlocked/conceptronicipcam_multiplevulnerabilities

[CVE-2018-6407 & CVE-2018-6408] Conceptronic IPCam Administration panel CSRF and Denial of Service

csrf denial-of-service disclosure vulnerabilities

Last synced: 20 Nov 2024

https://github.com/bringyourownideas/silverstripe-composer-security-checker

Provides information if your SilverStripe application uses dependencies with known vulnerabilities.

composer silverstripe silverstripe-maintenance vulnerabilities

Last synced: 10 Oct 2024

https://github.com/paulveillard/cybersecurity-vulnerability-management

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Software Vulnerabilities Management Process in Cybersecurity

vulnerabilities vulnerability vulnerability-assessment vulnerability-detection vulnerability-management vulnerability-research vulnerability-scanners vulnerability-scanning

Last synced: 07 Dec 2024

https://github.com/zupit/horusec-examples-vulnerabilities

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

analysis cd ci cli golang hacktoberfest java kotlin netcore python ruby sast sast-analysis scanner security security-development security-flaws static-analysis terraform vulnerabilities

Last synced: 08 Nov 2024

https://github.com/jgamblin/cvereview

2023 CVE Data Review

cve nvd vulnerabilities

Last synced: 11 Nov 2024

https://github.com/damiencarol/vulnerabilities

Python framework to manipulate vulnerabilities.

python vulnerabilities vulnerability-management vulnerability-scanners

Last synced: 15 Nov 2024

https://github.com/pierluigi/azure-devops-demo

Basic Node App built with Azure DevOps for demos

azure-devops channels codecov demo vulnerabilities

Last synced: 27 Oct 2024

https://github.com/s3rgeym/x-access-dumper

Dumps everything web accessible: git repos, files from .DS_Store, sql dumps, backups, configs...

dumper hacking vulnerabilities

Last synced: 05 Nov 2024

https://github.com/rtfmkiesel/loldrivers-webclient

Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io

drivers golang mitre vulnerabilities wasm windows

Last synced: 27 Nov 2024

https://github.com/anthonyharrison/sbom-manager

Manage collection of SBOMs (Software Bill of Materials)

cyclonedx devsecops sbom sbom-repository sbom-tool security spdx vulnerabilities

Last synced: 07 Nov 2024

https://github.com/asos/snyker

An opinionated, heavy-handed wrapper around Snyk.

cli security snyk snyk-cli vulnerabilities vulnerable-paths

Last synced: 19 Nov 2024

https://github.com/efchatz/quic-attacks

Attacks against QUIC (CVE-2022-30591)

cve-2022-30591 flooding quic slowloris vulnerabilities

Last synced: 30 Oct 2024

https://github.com/reconmap/mobile-client

React-native based mobile client for Reconmap

android infosec mobile pentesting react-native security vulnerabilities

Last synced: 11 Nov 2024

https://github.com/demining/cold-and-hot-wallets

Cold Wallets and Hot Wallets how to find vulnerabilities and eliminate various attacks on the Blockchain

attack attacker attacks bitcoin bitcoin-transaction bitcoin-wallet blockchain coldwallet coldwaters cryptocurrency exploit exploits hack hacking vulnerabilities vulnerability

Last synced: 11 Jan 2025

https://github.com/anthonyharrison/csaf

CSAF generator and validator

csaf devsecops sbom security vex vulnerabilities

Last synced: 07 Nov 2024

https://github.com/Retr0-code/SignHere

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.

automation build-tool builder cve cve-2017-11882 equation malicious microsoft office python3 rtf vulnerabilities

Last synced: 21 Nov 2024

https://github.com/software-engineering-and-security/confuzzion

Confuzzion is a Java Virtual Machine (JVM) fuzzer generating Java programs to find bugs and vulnerabilities in the Java VM.

bug code-generation crashes fuzzer java java-virtual-machine java-virtual-machine-fuzzer jvm jvm-fuzzer jvm-fuzzing security soot testing type-confusion vulnerabilities vulnerability

Last synced: 31 Dec 2024

https://github.com/logchange/eir

🐛🗡️👩‍⚕️ eir is a tool to report system vulnerabilities 👩‍⚕️🗡️🐛

docker gitlab graalvm java micronaut report security security-tools vulnerabilities

Last synced: 28 Nov 2024

https://github.com/l1ghtn1ng/mutillidae-ansible

Ansible playbook to install Mutillidae which is a vulnerable web app by design

ansible ansible-playbook infosec labs vulnerabilities vulnerable

Last synced: 13 Oct 2024

https://github.com/chriszarate/know-your-deps

Picks a random dependency from your project and splains it to you.

npm security vulnerabilities

Last synced: 19 Oct 2024

https://github.com/jgamblin/CPEData

NVD CPE Data

cpe cve nvd vulnerabilities

Last synced: 21 Nov 2024

https://github.com/paulveillard/cybersecurity-dynamic-analysis

An ongoing & curated collection of awesome vulnerability scanning software, libraries and frameworks, best guidelines and technical resources and most important dynamic application security testing (DAST)

dast dynamic-analysis dynamic-analysis-engines sast static-analysis vulnerabilities vulnerability-assessment vulnerability-identification vulnerability-management vulnerability-scanner vulnerability-scanners

Last synced: 07 Dec 2024

https://github.com/whomrx666/xninjaz

Xninjaz is a powerful and versatile multi-vulnerability scanner designed to detect various web application vulnerabilities, including Local File Inclusion (LFI), Open Redirects (OR), SQL Injection (SQLi), and Cross-Site Scripting (XSS). This tool was created by Mr.X

kali-linux lfi-vulnerability linux or-scanner sql-vulnerability-scanner termux termux-tool vulnerabilities vulnerabilities-scanner xninjaz xss-vulnerability

Last synced: 13 Oct 2024

https://github.com/jgamblin/cpedata

NVD CPE Data

cpe cve nvd vulnerabilities

Last synced: 10 Jan 2025

https://github.com/nozaq/security-organizations-jp

日本国内のセキュリティ関連機関・団体をまとめていきます。

compliance cybersecurity security threat-intelligence vulnerabilities

Last synced: 14 Dec 2024

https://github.com/paulveillard/cybersecurity-ssrf

An ongoing & curated collection of awesome web vulnerability - Server-side request forgery software practices and remediation, libraries and frameworks, best guidelines and technical resources about SSRF

cybersecurity mitigation remediation security security-tools server-side server-side-request-forgery ssrf vulnerabilities vulnerability vulnerability-assessment vulnerability-detection vulnerability-management

Last synced: 07 Dec 2024

https://github.com/th3s4mur41/demo-auto-security-release

How to leverage GitHub and semantic release to reduce vulnerabilities in your packages

article blog blogging demo dependabot dependencies github-actions security semantic-release vulnerabilities

Last synced: 28 Oct 2024

https://github.com/grdashark/yrdsb-password-cracker

A password cracker using a dictionary attack or a brute-force attack to crack a YRDSB account's password.

brute-force dictionary-attack ethical-hacking ethical-hacking-tools hacking password password-cracker password-cracking vulnerabilities vulnerability

Last synced: 31 Dec 2024

https://github.com/desmondsanctity/cve-2022-44311

Out-Of-Bounds Read in html2xhtml : CVE-2022-44311

advisory security vulnerabilities vulnerability-assessment

Last synced: 26 Dec 2024

https://github.com/snyk/python-fix

🔓 Snyk ecosystem remediation strategies used with Snyk CLI to automatically remediate fixable issues.

security security-tools snyk vulnerabilities

Last synced: 10 Nov 2024

https://github.com/fear2o/scanshield

ScanShield is an advanced vulnerability scanner built to identify common web security flaws such as SQL Injection, XSS, LFI, RFI, directory listing issues, and security header misconfigurations.

ethical-hacking hacking hacking-tool lfi-detection lfi-exploit lfi-exploitation lfi-vulnerability python python3 sql vulnerabilities vulnerability vulnerability-detection vulnerability-scanners xss xss-attacks xss-detection xss-exploitation xss-vulnerability

Last synced: 09 Jan 2025

https://github.com/farinap5/vulnmanager

Vulnerability Manager - For web application.

manager python3 sqlite3 vulnerabilities

Last synced: 19 Nov 2024

https://github.com/avishayil/python-snyk-test

A tool that wraps pysnyk library for easier usage from command line interfaces

oss pypi python snyk test vulnerabilities

Last synced: 02 Nov 2024