vulnerability-assessment

There are 300 repositories under vulnerability-assessment topic.

  • projectdiscovery/nuclei

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    Language:Go21.2k2382.5k2.5k
  • h4cker

    The-Art-of-Hacking/h4cker

    This repository is primarily maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), artificial intelligence security, vulnerability research, exploit development, reverse engineering, and more.

    Language:Jupyter Notebook19.3k929993.5k
  • CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Language:Shell13.6k3428611.5k
  • future-architect/vuls

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

    Language:Go11.1k3266011.2k
  • ysrc/xunfeng

    巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

    Language:Python3.6k1811911.3k
  • scipag/vulscan

    Advanced vulnerability scanning with Nmap NSE

    Language:Lua3.5k1350669
  • greenbone/openvas-scanner

    This repository contains the scanner component for Greenbone Community Edition.

    Language:Rust3.5k82163635
  • NVIDIA/garak

    the LLM vulnerability scanner

    Language:Python3.2k31602270
  • evyatarmeged/Raccoon

    A high performance offensive security tool for reconnaissance and vulnerability scanning

    Language:Python3.1k10837402
  • cve-search/cve-search

    cve-search - a tool to perform local searches for known vulnerabilities

    Language:Python2.3k107504595
  • archerysec/archerysec

    ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

    Language:JavaScript2.3k94264505
  • anouarbensaad/vulnx

    vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.

    Language:Python1.9k5359344
  • skavngr/rapidscan

    :new: The Multi-Tool Web Vulnerability Scanner.

    Language:Python1.8k6838407
  • XAttacker

    Moham3dRiahi/XAttacker

    X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

    Language:Perl1.6k1000471
  • felixgr/secure-ios-app-dev

    Collection of the most common vulnerabilities found in iOS applications

  • olacabs/jackhammer

    Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

    Language:Java7226094162
  • m0nad/HellRaiser

    Vulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.

    Language:Ruby5623313143
  • frizb/Vanquish

    Vanquish is Kali Linux based Enumeration Orchestrator. Vanquish leverages the opensource enumeration tools on Kali to perform multiple active information gathering phases.

    Language:Python5054010132
  • SkyLined/BugId

    Detect, analyze and uniquely identify crashes in Windows applications

    Language:Python5023112190
  • nerve

    PaytmLabs/nerve

    NERVE Continuous Vulnerability Scanner

    Language:Python4542919115
  • we1h0/SecurityManageFramwork

    Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management, account management, knowledge base management, security scanning automation function modules, and can be used for internal security management. This platform is designed to help Party A with fewer security personnel, complicated business lines, difficult periodic inspection and low automation to better achieve internal safety management.

    Language:Python426265157
  • flipkart-incubator/watchdog

    Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.

    Language:Python4153012103
  • mageni

    mageni/mageni

    Open-source vulnerability scanner

    Language:NASL41320047
  • sethsec/celerystalk

    An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

    Language:Python399258269
  • Martyx00/VulnFanatic

    A Binary Ninja plugin for vulnerability research.

    Language:Python28312636
  • InfoSecWarrior/Offensive-Payloads

    List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.

    Language:PHP257100101
  • greenbone/gsa

    Greenbone Security Assistant - The web frontend for the Greenbone Community Edition

    Language:JavaScript22217174100
  • Hrishikesh7665/Android-Pentesting-Checklist

    Delve into a comprehensive checklist, your ultimate companion for Android app penetration testing. Identify vulnerabilities in network, data, storage, and permissions effortlessly. Boost security skills with essential tools and user-friendly guides. Elevate Android security seamlessly!

  • Vailyn

    VainlyStrain/Vailyn

    A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

    Language:Python19862525
  • bulwark

    softrams/bulwark

    An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

    Language:TypeScript1771014937
  • greenbone/gvm-tools

    Remote control your Greenbone Community Edition or Greenbone Enterprise Appliance

    Language:Python171187590
  • OWASP/ASST

    OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

    Language:JavaScript1628535
  • UnSAFE_Bank

    lucideus-repo/UnSAFE_Bank

    Vulnerable Banking Suite

    Language:PHP155121483
  • target/portauthority

    API that leverages Clair to scan Docker Registries and Kubernetes Clusters for vulnerabilities

    Language:Go15117821
  • Rezilion/mi-x

    Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability (runtime execution, configuration, permissions, existence of a mitigation, OS, etc..)

    Language:Python140629