vulnerability-detection

There are 687 repositories under vulnerability-detection topic.

  • aquasecurity/trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    Language:Go29.7k1823k2.8k
  • projectdiscovery/nuclei

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    Language:Go25.4k2432.7k2.9k
  • CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Language:Shell14.8k3409081.6k
  • wazuh/wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

    Language:C13.9k22022.5k2k
  • future-architect/vuls

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

    Language:Go11.8k3256331.2k
  • projectdiscovery/nuclei-templates

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    Language:JavaScript11.3k2021.9k3.1k
  • kubescape

    kubescape/kubescape

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

    Language:Go11k93528886
  • dependency-check/DependencyCheck

    OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

    Language:Java7.3k1755.2k1.4k
  • GhostTroops/scan4all

    Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

    Language:Go5.9k67106707
  • ThreatMapper

    deepfence/ThreatMapper

    Open Source Cloud Native Application Protection Platform (CNAPP)

    Language:TypeScript5.2k58609638
  • greenbone/openvas-scanner

    This repository contains the scanner component for Greenbone Community Edition.

    Language:Rust4.1k88182724
  • Arachni/arachni

    Web Application Security Scanner Framework

    Language:Ruby4k1991k785
  • scipag/vulscan

    Advanced vulnerability scanning with Nmap NSE

    Language:Lua3.7k1330689
  • ysrc/xunfeng

    巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

    Language:Python3.6k1811921.3k
  • dependency-track

    DependencyTrack/dependency-track

    Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

    Language:Java3.4k702.4k687
  • cve-search/cve-search

    cve-search - a tool to perform local searches for known vulnerabilities

    Language:Python2.5k101527614
  • Checkmarx/kics

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Language:Open Policy Agent2.5k262k349
  • protectai/vulnhuntr

    Zero shot vulnerability discovery using LLMs

    Language:Python2.4k3417274
  • anouarbensaad/vulnx

    vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.

    Language:Python2k5262350
  • skavngr/rapidscan

    :new: The Multi-Tool Web Vulnerability Scanner.

    Language:Python1.9k6939427
  • safety

    pyupio/safety

    Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.

    Language:Python1.9k32250167
  • 0xInfection/TIDoS-Framework

    The Offensive Manual Web Application Penetration Testing Framework.

    Language:Python1.8k124110393
  • top25-parameter

    lutfumertceylan/top25-parameter

    For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

  • wagiro/BurpBounty

    Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.

    Language:Java1.8k59103341
  • murphysecurity/murphysec

    An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

    Language:Go1.7k2645180
  • metlo-labs/metlo

    Metlo is an open-source API security platform.

    Language:TypeScript1.7k143299
  • aquasecurity/trivy-operator

    Kubernetes-native security toolkit

    Language:Go1.7k10787253
  • XAttacker

    Moham3dRiahi/XAttacker

    X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

    Language:Perl1.7k1030474
  • wireghoul/graudit

    grep rough audit - source code auditing tool

    Language:Shell1.7k3627253
  • 0xricksanchez/paper_collection

    Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read

    Language:Python1.3k1022130
  • Lucifer1993/SatanSword

    红队综合渗透框架

    Language:Python1.2k186207
  • bitquark/shortscan

    An IIS short filename enumeration tool

    Language:Go1k821105
  • Open-Source-Security-Guide

    mikeroyal/Open-Source-Security-Guide

    Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

    Language:Go1k28393
  • CERT-Polska/Artemis

    A modular vulnerability scanner with automatic report generation capabilities.

    Language:Python9671912285
  • wazuh/wazuh-docker

    Wazuh - Docker containers

    Language:Shell95546888503
  • toolswatch/vFeed

    The Correlated CVE Vulnerability And Threat Intelligence Database API

    Language:Python94411270242