Awesome Security Vulnerability Project(By LLM)
Project Introduction
This project uses a large model combined with a crawler to retrieve all projects on GitHub that contain valuable vulnerability information, vulnerability POCs, or rule information. It automatically identifies the project's directory structure and Readme information, then summarizes, analyzes, and categorizes them. The aggregated projects can help security industry practitioners collect vulnerability information, POC information, rules, and more.
LLM Analysis Process
- Based on GithubGather, use a Token proxy pool to traverse and crawl GitHub project data
- Based on aiflows, perform LLM analysis on the crawled data to produce results
Detailed plans will be updated in aiflows, currently not yet complete
Security Learning & Resources
- zongdeiqianxing/WebSecurityArticles
- A collection of Markdown documents containing multiple high-quality web security articles, providing learning resources for Web security
- zmerry/z-marvel.github.io
- Security-related resources and tools, including files and subdirectories from 2017-2019.
- zj1244/Blog
- Learning reference resources for Kubernetes, Docker, security technology articles and tutorials
- YOURLEGEND/xie-note
- Cybersecurity learning resource library, containing learning materials on various topics such as CTF, Web security, intranet penetration, suitable for learning and research in the cybersecurity field.
- yongsheng220/CTF
- Cybersecurity problem bank covering SQL injection, XSS attacks, CWE common vulnerability exploitation, suitable for learning and practicing cybersecurity techniques.
- yingshang/CybersecurityNote
- Security knowledge learning and recording project, covering red team offense and defense, penetration testing, code auditing, and more.
- Xsw6/JavaSec
- Java security study notes, involving ASM, JDBC, Spring, Shiro, and other aspects, with rich practical cases.
- xqx12/daily-info
- Contains technical documents from 2020 to 2023, used for tracking technological development.
- xitu/gold-miner
- A community that translates high-quality internet technology articles, including security-related content.
- xianshang/1earn
- Open source learning resource library, sharing security and operations knowledge
- wukong-bin/PeiQi-WIKI-POC
- PeiQi WiKi-POC library provides knowledge about environment setup, POC, and vulnerability principles, helping people learn various vulnerability-related information.
- wgpsec/peiqi-wiki
- WgpSec POC library is an open-source collection of network vulnerability POCs, including environment setup, POCs, and vulnerability principles. It supports online browsing, offline download, and contribution features.
- timlzh/webArmory
- Web Armory is a CVE knowledge base that can be run via Docker or local compilation, providing convenient vulnerability search functionality.
- Threekiii/Vulnerability-Wiki
- An open-source security knowledge base integrating multiple vulnerability libraries, offering Docker deployment options, suitable for security professionals and technology enthusiasts.
- TheTh1nk3r/RedTeamLinks
- Cybersecurity-related resource links, including offense and defense testing manuals, intranet security documents, learning manual-related resources, checklists and basic security knowledge, product design documents, learning ranges, vulnerability reproduction, open-source vulnerability libraries, etc., suitable for professionals in cybersecurity, red team attacks, and other fields.
- telekom-security/telekom-security.github.io
- Security blog built with Jekyll, providing the latest cybersecurity news and advice
- SummerSec/BlogPapers
- Personal blog website containing articles on Java programming language and security domain knowledge
- SpeeDr00t/speedr00t.github.com
- Provides security-related resources and tools
- Spacial/awesome-csirt
- CSIRT GitHub project collects incident response related resources, including books, links, and a list of security projects. It also includes tools for encoding, encryption, hashing, and obfuscation, as well as search engines for malware analysis, vulnerabilities, and exploits. The project also contains information on incident response frameworks and standards, such as the CERT model and SIM v3 model.
- Simpsonpt/AppSecEzine
- A regularly published open-source cybersecurity news magazine covering various information security issues and the latest hot topics.
- SherryLiGit/penetration-handbook
- Target chain penetration testing guide manual, providing guidance for target chain penetration testing.
- shengshengli/vulnerability-paper
- An open-source project collecting various cybersecurity-related resources, including CISP_PTE, vulnerabilities, bypasses, and evasion content, aiming to provide a security resource library for learning and reference.
- SexyBeast233/SecBooks
- SecBooks is a project containing articles from various we-media accounts, including multiple articles on security, such as vulnerability reproduction, SQL injection, etc., and provides plugin support.
- ruanyf/weekly
- Technology enthusiast weekly, collecting tech content worth sharing each week, including AI, cybersecurity, and other fields. Created by Ruanyf, readers can submit issues to share content. Provides search functionality, with a history of over two years, very valuable.
- root26/bcak
- Baige Wiki is a beta version of the Baize Sec team, containing technical summaries and original articles on cybersecurity, and provides contribution guidelines and document storage format requirements.
- reidmu/sec-note
- Security notes/tools/vulnerability collection, including penetration ideas, vulnerability research, etc.
- ReAbout/web-sec
- Provides explanations of web security, vulnerability understanding, vulnerability exploitation, code auditing, and penetration testing.
- PeiQi0/PeiQi-WIKI-Book
- A knowledge base for cybersecurity practitioners, covering vulnerability research, code auditing, CTF competitions, red-blue confrontation, etc., solving the problems of scattered security information and hard-to-find security materials, helping cybersecurity practitioners build a secure internet.
- password520/vulnerability-paper
- An open-source project of cybersecurity articles, tools, and techniques, including articles related to certification exams, vulnerabilities, bypasses, and range reproduction, providing search functionality and file categorization for learning and reference.
- NuclearAtk/lcx.cc
- Personal blog website, may have XSS attack risks, can be used as learning material and practice target.
- MrWQ/vulnerability-paper
- Open-source project of cybersecurity articles, tools, and techniques, including CISP_PTE, vulnerabilities, range reproduction, etc., with article search functionality
- lal0ne/HW
- Offense and defense manual and vulnerability POCs, providing security defense knowledge and practical experience.
- kb5000/kb5000.github.io
- May contain CSS, JS, images, etc., possibly a personal blog website. Has potential security risks, requires further review.
- kamranahmedse/developer-roadmap
- This is a community-driven developer roadmap, articles, and resources repository, providing learning materials for multiple programming languages and technologies.
- JnuSimba/MiscSecNotes
- Web security, penetration testing study notes and material collection, covering HTTP protocol, cross-site scripting, SQL injection, PHP security, and other topics, including original content and organized understandings of online articles.
- jas502n/Security_Article
- Scrapy crawler project for storing and managing security articles and links
- hktalent/MyDocs
- A report of security vulnerabilities containing multiple CVE IDs, involving multiple open-source website programs and their components such as Joomla, Nginx, WordPress.
- hhhparty/security
- Personal teaching notes, study notes, and security gadgets
- Haoyunforever/Study
- Intranet penetration and range practical experience study notes and related tools to enhance security skills.
- H3rmesk1t/Security-Learning
- Security-Learning is a GitHub project providing learning materials on various security topics, including AISec, BinarySec, DatabaseSec, JavaSec, NodejsSec, PHPSec, Penetration, and PythonSec.
- goncalor/cve-ark
- This project contains data from 1999 to 2024, may involve security risks, need to strengthen data protection measures.
- github/advisory-database
- An open-source security vulnerability database containing security advisories and vulnerability information from various sources, stored in OSV standard format. Users can update or modify information in the database by submitting PRs.
- friends-of-presta/security-advisories
- A platform providing security vulnerability information for PrestaShop modules, including search API and RSS feeds, enhancing the security of the entire ecosystem.
- ffffffff0x/1earn
- Open-source learning resource library, sharing knowledge and practices in various security fields, covering multiple sub-projects and detailed learning paths.
- euphrat1ca/Security-List
- Comprehensive learning and reference resources in application security, wireless proximity, digital forensics, and other fields
- dream0x01/spear-framework
- Spear-framework is a security research platform for collecting and organizing various vulnerabilities and articles, allowing rapid construction of a security knowledge system.
- cloudsecurityalliance/gsd-database
- The Global Security Database (GSD) is an open-source project aimed at creating a community-driven vulnerability database. It includes a vulnerability community guide and two main repositories—database and tools. Data can be accessed via GitHub, API, or web interface.
- bfengj/CTF
- Study notes on penetration testing, JavaScript, Go language, Java security, and some competition problem attachments.
- batermj/data_sciences_campaign
- Data scientist series courses, covering multiple programming languages and database technologies, as well as data analysis practical training.
- BaizeSec/bylibrary
- Baige Wiki is the beta version of Baize Sec team, providing documents and tutorials related to cybersecurity, contributions and learning are welcome.
- astaxie/build-web-application-with-golang
- Open-source tutorial for building web applications in multiple language versions, risk of translation errors, need to verify content accuracy.
- apachecn/pentesttools-blog-zh
- Chinese translation version of PentestTools blog, covering learning materials on multiple security technologies.
- apachecn/kalilinuxtutorials-zh
- Provides security domain knowledge learning resources, including documents, tutorials, and tools.
- ADummmy/vulhub_Writeup
- Web application vulnerability learning and research resources
- adminlove520/DFYXSec-Wiki-Book
- Security knowledge sharing platform built with VuePress and Ant Design, providing quick start guide and local development environment, sharing and disseminating security knowledge.
- 119dd1bd86728b407fe82fce1f8b9369/catalogue03
- A security project containing directories for 2021, 2022, and 2023, with a README providing information on the project.
- 0x783kb/Security-operation-book
- Security operation manual covering Web, Windows AD, and Linux, suitable for ATT&CK techniques, simulation testing, and detection requirements.# Security Tools & Scripts
- zhzyker/exphub
- Exphub is a security tool project containing multiple exploit scripts, providing exploit support for well-known systems and their versions such as Weblogic, Spring, Struts2, etc. It covers various types of exploits including RCE, Exploit, Command execution, helping security experts conduct penetration testing and vulnerability discovery.
- zema1/yarx
- Yarx is a security tool that automatically generates a Server based on xray's YAML PoC rules and uses xray to scan that Server for vulnerability detection.
- zan8in/afrog
- A security tool for bug bounties, penetration testing, and red teams, offering PoC, GitHub Release, Wiki and other features.
- yuyudhn/yuyudhn.github.io
- This project includes various frontend technologies and security-related configuration files and certificates, usable for security testing and research.
- ysrc/xunfeng
- Xunfeng is a vulnerability rapid emergency and cruising scanning system suitable for enterprise intranets, implementing asset identification and vulnerability detection through a network asset identification engine and a vulnerability detection engine.
- yaklang/yakit-store
- Yak contains multiple submodules such as codec, mitm, module, packet, and portscan, which can be used for implementing network security-related functions.
- y1ng1996/poc
- BugScan: Network security vulnerability scanning and testing tool, implementing automated penetration testing functions.
- xx-zhang/Medusa
- A security toolkit based on secondary development of Medusa, containing multiple vulnerability PoCs and automated penetration tools, supporting Docker deployment.
- xinyisleep/pocscan
- A security toolkit containing a large number of PoC checks, usable for detecting security vulnerabilities in various open-source software and systems. Includes vulnerability scanning scripts for OA systems such as Weaver, Tongda, Zhiyuan, and is continuously updated. Uses the pocsuite library for operation, requires Python environment.
- xanszZZ/pocsuite3-poc
- This project contains various security vulnerabilities and penetration testing tools, usable for detecting and fixing security vulnerabilities in servers, applications, and network devices.
- x00itachi/msf-ref-collector
- Metasploit References Collector, organizes existing references from the Metasploit Framework into CSV format.
- x-stream/xstream
- XStream is a Java to XML deserialization tool, providing high performance and flexibility, supporting custom converters and optional runtime extensions.
- wonderkun/crawler
- Automated article crawling, using Python crawler technology to automatically fetch and organize security-related articles from anquanke.com and xz.aliyun.com, aiming to provide a convenient way to obtain articles.
- Wker666/Cheetah
- Contains various penetration testing tools such as SQL injection, web attacks, binary attacks, etc., suitable for experiments and research in the security field.
- WingsSec/Meppo
- Meppo is a vulnerability detection framework that provides interfaces for FOFA, SHODAN, and Hunter API, and supports single-target and multi-target single PoC or module monitoring.
- windwant/windwant-service
- WindWant Service is an open-source project containing various application examples, including practice and learning of multiple security-related technologies, such as encryption algorithms, consensus algorithms, network programming, message queues, etc.
- wick2o/osf_db
- sf-search.py, used to search for software in the security vulnerability database sfocus.db, supports remote or local vulnerability filtering.
- wh1t3p1g/MonitorClient
- MonitorClient is a C/S-based website source code real-time monitoring and webshell detection/kill tool, featuring file change monitoring and webshell detection, supporting Windows/Linux platforms, with encrypted communication for data security.
- wagiro/BurpBounty
- Burp Bounty is a Burp Suite extension for creating custom scanning rules, providing a user-friendly graphical interface to improve the efficiency of active and passive scanners. It includes preset configuration files, usage instructions, and community-contributed configuration files.
- w3bd0gs/cocoworker
- A self-use web scanner containing about 2k PoCs, planned to port w9scan, and designed user and scan result table structures.
- w-digital-scanner/w9scan
- All-round website vulnerability scanner, containing 1200+ plugins, supporting fingerprint detection, service discovery, and generating HTML format reports.
- vulsio/msfdb-list
- msfdb-list is a tool for automatically collecting vulnerability information and storing it in a parseable format, providing convenient and fast security threat intelligence management.
- vulsio/goval-dictionary
- goval-dictionary is a tool for generating and querying local SQLite format OVAL dictionaries, supporting fetching vulnerability dictionary data from multiple databases and providing a server mode for simple queries.
- vulsio/gost
- gost is a security vulnerability tracker for building a local copy, updating via email or Slack notifications.
- vulsio/go-msfdb
- Search for CVEs in Metasploit-Framework modules, supports local deployment of multiple databases, easy to use.
- veo/vscan
- VScan is an open-source, lightweight, fast, cross-platform website vulnerability scanning tool that helps users quickly detect website security issues. It features fast port scanning, fingerprint detection, login password brute force, PoC detection, and sensitive file detection, supporting multiple input and output types.
- Tyaoo/picker
- Security news crawler and push program based on Github Action, supporting multiple types of security information push.
- Tyaoo/IoT-Vuls
- IoT-Vuls is a security scanning tool for IoT devices, detecting device vulnerabilities and providing fix recommendations.
- trganda/dockerv
- Docker environment supporting vulnerability analysis and development, containing multiple pre-built Docker images and usage instructions, convenient for vulnerability scanning and reproduction.
- tr0uble-mAker/POC-bomber
- A vulnerability detection/exploitation tool for quickly gaining target server privileges using a large number of PoCs/EXPs for high-impact vulnerabilities.
- topscoder/nuclei-wordfence-cve
- Nuclei + Wordfence = CVE Scanning tool. This project provides a large set of updated Nuclei templates for scanning vulnerabilities in WordPress. These templates are based on security reports from Wordfence.com. It is a valuable resource for anyone responsible for managing websites that use WordPress, easy to use, up-to-date, and open-source, so you can modify it to suit your specific needs. If you find this project useful, please consider giving it a star on GitHub. Your support helps make this project better.
- tiaotiaolong/TTLScan
- TTLScan is a plugin-based vulnerability scanner framework supporting multiple input sources and engines, including ip, url, Zoomeye, etc. It can automatically obtain target sets and provides PoC script format specifications. It has implemented detection for RedisUn, RedisGetShell, Struts2 series vulnerabilities, and supports multi-threading and distributed task processing.
- Threekiii/Awesome-POC
- This project provides various open-source security tools and projects, covering a wide range of common security issues and vulnerabilities, including but not limited to permission management, file upload, SQL injection, remote code execution, etc. These tools and projects can help security personnel conduct penetration testing and vulnerability scanning to ensure system security.
- thetowsif/nuclei-template-fetcher
- This project is a repository for collecting Nuclei templates from open-source projects on GitHub, providing templates from 153 source repositories, aiming to share and check templates to avoid false negatives.
- thanhnx9/nuclei-templates-cutomer
- This project, named nuclei-templates-cutomer, includes community templates, full web crawling, Swagger, and other features used for automated testing in the security field.
- terry494/fengchenzxc.github.io
- Network security audit tool, providing vulnerability scanning, risk assessment, and other functions to ensure system security.
- syadg123/Medusa-
- Medusa Scan is an open-source security scanning tool, supporting Bash and Bot versions, capable of website vulnerability scanning, password brute force, etc. Users must comply with relevant laws and regulations and pay attention to protecting personal privacy.
- SuperKieran/WooyunDrops
- Wooyun Drops is a static version of Wooyun Drops, providing full-text search functionality, supporting HTTPS and customizable search engine.
- Str1am/OAScan
- Tool for scanning OA system vulnerabilities, supporting various parameters, including specifying URL for testing, specifying OA system for scanning, and specifying single PoC for scanning.
- songlh/bigsecurity
- VulScan is a vulnerability scanner supporting multiple scan modes, customizable scan rules, helping discover security vulnerabilities in the system.
- Sharpforce/cybersecurity
- MyExpense: A Python open-source tool for simulating user operations and collecting data, including virtual machine IP address display and related articles, book reading notes.
- shakenetwork/VulApps
- VulApps is a Docker image library collecting various vulnerability environments and security tool environments, convenient for security testing and learning. Includes various web applications (e.g., Struts2, WordPress), network devices (e.g., Cisco, Nginx), and security tools (e.g., Xunfeng, Ant). Each environment has a corresponding tag, users can easily pull and run via docker commands.
- shadow1ng/fscan
- fscan is an intranet comprehensive scanning tool for intranet penetration testing, including host discovery, port scanning, service brute force, etc.
- sepehrdaddev/zap-scripts
- ZAP plugins, active and passive scanning scripts for discovering vulnerabilities and secrets.
- selinuxG/Golin
- Features include host discovery, vulnerability scanning, subdomain scanning, asset scanning, various service database brute force, and PoC scanning. Supports web mode preview, weak password/unauthorized access scanning, etc.
- seifreed/VirusShare
- VirusShare contains static data extracted from malware repositories for academic use.
- SecWiki/CMS-Hunter
- CMS-Hunter is a tool for vulnerability scanning and remediation of various CMS systems, helping users promptly discover and fix security risks in their systems.
- scipag/AttackToolKit
- ATK is a customizable security scanning and exploitation tool for detecting specific vulnerabilities. It combines a security scanner (e.g., Nessus) and an exploitation framework (e.g., Metasploit), works without interaction, and allows users to customize plugins, checks, enumeration, and reporting according to their needs.
- saucer-man/saucerframe
- Batch PoC detection framework, supporting multi-threaded concurrency/co-routine requests, multiple target specification methods, multiple API target acquisition, and extensible functions.
- sari3l/Poc-Monitor
- Used to monitor CVE vulnerability information updates and provide notification features. Users can query files to get the latest vulnerability information, or set notification rules to automatically send notifications when new vulnerability information appears.
- ryanmrestivo/red-team
- Provides various tools and information used by security professionals, including notes on red team materials, testing techniques, and network scanning tools. Also includes descriptions of TCP/IP socket programming APIs and examples of how to use them to transfer files and establish remote shells across different networks. Additionally contains information on PowerShell and its application in network penetration testing. Overall, this project is a comprehensive resource for anyone interested in network security and penetration testing.
- Ricky-Wilson/CodeBase
- CodeArchive provides code examples in multiple programming languages to help users understand and master related technologies. Some examples also involve solutions to security-related issues, offering practicality and security.
- rapid7/metasploit-framework
- Metasploit is an open-source penetration testing tool, providing detailed documentation and tutorials to help users install and use it.
- randomtable/ChimeraOS
- This project provides a distributed IRC service aimed at private communication. It leverages Docker and the Tor network model to scale hidden services, building a scalable and highly available communication network. The project has strong security features, such as using distributed hidden services to protect user privacy, as well as scalability and high availability.
- rabbitmask/AssetsHunter
- Asset hunting framework supporting multiple information collection and data deduplication features.
- r00tSe7en/gitbook
- Online tool collection providing various information gathering and search functions, such as DNS, search engines, subdomain/IP/旁站C段, email collection, etc.
- qsdj/cncs-armory-ktrimisu
- CScan is a Python-based security automated scanning framework supporting multiple strategies and vulnerability detection, and includes automatic formatting and static analysis tools.
- qingchenhh/qc_poc
- PoC collection, including organized days from HVV 2023, some README, and miscellaneous PoCs, mainly used for security technology verification and sharing.
- qazbnm456/awesome-cve-poc
- Collects common vulnerability PoCs with detailed descriptions.
- projectdiscovery/nuclei-templates
- Nuclei Templates is a community-maintained collection of templates for the nuclei engine to identify security vulnerabilities in applications. This repository contains various templates provided by the team and contributed by the community, organized by directory and severity level. The project aims to provide a comprehensive resource for security professionals to quickly and easily scan for vulnerabilities in systems.
- praetorian-inc/purple-team-attack-automation
- Purple Team ATT&CK Automation is a Metasploit Framework project that automates MITRE ATT&CK TTPs as post-exploitation modules, enabling blue teams to simulate attacker behavior and test their detection and response capabilities. The project includes over 100 automated TTPs and can emulate the functionality of other tools such as in-memory .NET execution. The project is open-source and available on GitHub. To use it, users must have Docker installed and can follow the instructions in the project README.
- pokerfacett/freebuf_scrapy
- Crawler program for collecting articles and their keywords from freebuf, facilitating security research and learning.
- pimps/CVE-2017-1000486
- Security tool exploiting padding oracle vulnerabilities.
- pedrib/PoC
- Security research repository created by Pedro Ribeiro, containing research notes, exploit code, and vulnerability information, released under the GPLv3 license.
- pdelteil/BugBountyReportTemplates
- Provides various vulnerability report templates suitable for security researchers and developers.
- Patrowl/PatrowlHearsData
- PatrowlHearsData is an open-source vulnerability intelligence platform that collects and provides CVE, CPE, CWE, and Exploit reference data, offering a public repository of raw data and scraping scripts.
- patrickmpalmer/exploit-prediction-calculator
- exploit-prediction-calculator is a security tool for predicting and preventing potential exploit usage. It includes code in the UI, data_gathering, intelligence_engine, and user_interface directories, enabling real-time monitoring and warning of security threats and providing corresponding defense measures.
- ParrotSec-CN/ParrotSecCN_Community_QQbot
- ParrotSecCN_Community_QQbot is a QQ bot that provides functions such as searching forums, displaying vulnerabilities, system vulnerability scanning, and email sending.
- paralax/awesome-honeypots
- Awesome Honeypots is a GitHub repository collecting various open-source network and application honeypot tools, including web honeypots, database honeypots, etc., providing detailed usage guides and installation instructions, with PoC collection capabilities.
- OpenWireSec/metasploit
- Metasploit is a powerful network security tool for penetration testing and exploit development, released under the BSD license, providing detailed documentation and tutorials, and supporting user-customized extensions.
- opensec-cn/kunpeng
- Kunpeng is a security detection framework that can detect various types of security vulnerabilities, including databases, middleware, web components, CMS, etc. It provides multi-platform support, solves the wheel problem, and reduces wheel consumption. All collected vulnerabilities have been verified via PoC and theoretical judgment, without launching actual attacks.
- olbat/nvdcve
- This project provides JSON files for NVD and CVE® dictionaries, and can explore their modification history via Git. JSON files are generated and updated daily by NVD's JSON feed and Travis CI. Data can be accessed via https://olbat.github.io/nvdcve/CVE-YYYY-NNNN.json.
- ntop/ntopng
- ntopng is a network traffic monitoring application providing a web interface and improvements in performance, ease of use, and features, supporting multiple platforms with source code and precompiled packages available.
- njcx/pocsuite_poc_collect
- pocsuite_poc_collect is a tool that uses the pocsuite framework to collect PoC tools for vulnerability testing in the security field.
- neuvector/vul-source
- ubuntu-cve-tracker.commit is a security tool for tracking Ubuntu system vulnerabilities, providing related files and subdirectories.
- nbxiglk0/Note
- Network security audit tool, supporting vulnerability scanning, risk assessment, and other functions to ensure system security.
- NanJishen/nanjishen.github.io
- This project provides various security-related tools and scripts, including vulnerability scanning, penetration testing, security assessment, etc.
- Nan3r/myspider
- Contains spiders subproject, using scrapy and requests_html to crawl online jokes and news.
- mrojz/rconfig-exploit
- Contains exploit code and related documentation for SQL injection attacks and vulnerability detection.
- Mr-xn/Penetration_Testing_POC
- A collection of various penetration testing tools, scripts, and articles.
- Mr-xn/BurpSuite-collections
- Burp Suite plugin collection, including localized versions and automatic update scripts.
- merlinepedra/OA-EXPTOOL
- A Python tool for vulnerability detection in OA products, with a command-line interface and report generation, capable of detecting multiple vulnerabilities and supporting updates.
- mageni/mageni
- Mageni is an open-source vulnerability and attack surface management platform that helps organizations discover, assess, prioritize, and remediate vulnerabilities in their assets and services. It provides a faster, more enjoyable, and leaner vulnerability management experience, and supports various industries such as PCI DSS, NIST, HIPAA, ISO, NERC, FISMA, and NIS, meeting compliance requirements.
- luck-ying/Library-POC
- This project contains various open-source security-related projects, including but not limited to code audit, vulnerability discovery, security tool development, and vulnerability research.
- Lucifer1993/AngelSword
- AngelSword is a CMS vulnerability detection framework written in Python, helping security engineers quickly find vulnerabilities.
- lovechinacoco/https-github.com-mai-lang-chai-Middleware-Vulnerability-detection
- A tool for detecting vulnerabilities in various middleware products, supporting popular middleware such as Apache, Joomla, Harbor, Kibana, Jboss, Seeyon, ThinkCMF, PHP-FPM, and providing corresponding vulnerability scanning and remediation methods.
- LittleBear4/OA-EXPTOOL
- OA-EXPTOOL is an exploit framework for detecting common high-risk vulnerabilities in enterprise application systems. It uses YAML files for vulnerability verification and has an interactive command-line interface. It also supports batch scanning, error handling, result output, etc.
- likescam/AttackDetection
- Suricata PT Open Ruleset, containing a series of Suricata rules for detecting network security vulnerabilities and malicious activities, also provides PoC exploits and sample traffic data. These rules are optimized for TLS communication and use a custom SID range (10000000-10999999). The project is licensed under Apache 2.0.
- LHXHL/QiuPoc
- QiuPoc is an automated vulnerability detection tool written in Go, containing multiple known PoCs, supporting detection of single or batch targets.
- larsbijl/trending_archive
- This project contains daily GitHub trending information in multiple languages, serving as a reference for security personnel to understand the latest technology trends.
- lanjelot/kb
- Contains various types of penetration testing tools and resources covering networks, operating systems, databases, web applications, etc., suitable for security researchers and penetration testers.
- kylekirkby/Python-Exploit-Search-Tool
- A Python project for searching using Offensive Security's Exploit-db and Shodan's Exploit DB API. Includes display.py, exploitdb.py, main.py, and shodandb.py files, as well as directories for different platforms. A powerful tool for security professionals seeking system vulnerabilities.
- KTZgraph/sarenka
- Sarenka is an open-source intelligence tool for collecting and understanding attack surfaces. It can obtain information about internet-connected devices from search engines and provide Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE) databases, and a mapping from CVE to CWE. It also offers simple tools such as a hash calculator, Shannon entropy calculator, and basic port scanner.
- jorhelp/Ingram
- A scanning framework targeting network camera vulnerabilities, integrating multiple brand devices, supporting custom targets and ports, usable for security testing.
- jaeles-project/jaeles-signatures
- Plugin repository for the open-source vulnerability scanner Jaeles, containing various signature files for different targets, used to detect common vulnerabilities and misconfigurations.
- izj007/wechat
- WeChat favorites article list, used to store and display articles bookmarked by users in WeChat.
- Invicti-Security/netsparker-custom-security-checks
- Provides custom security checks for Invicti Standard's vulnerability detection functionality. These checks are written in JavaScript and can be used to identify potential vulnerabilities in HTTP responses. The project includes a directory structure and README file explaining how to use and contribute.
- ihebski/XSS-Payloads
- Contains various standard and latest XSS attack vector payload code examples.
- iamHuFei/HVVault
- HVVault is a security tool for detecting and exploiting some network vulnerabilities that emerged in 2023, integrating multiple PoC libraries based on Nuclei scanning templates.
- HorseLuke/drafts
- Tool for storing and sharing drafts, no special security features.
- hi-KK/VulDB_Spider
- A vulnerability database crawler tool based on the PySpider crawler framework, supporting crawling of domestic and international vulnerability databases such as NVD, CNVD, and CNNVD, and providing detailed vulnerability information display and query functions, making it convenient for users to obtain and handle security threats in a timely manner.
- HatBoy/Pcap-Analyzer
- A packet analysis tool developed in Python, supporting analysis of multiple protocols, including but not limited to network traffic, basic packet information, protocol analysis, security risk analysis, and extraction of sensitive data and specific protocol transfer files from packets. It also provides a function to plot the latitude and longitude map of accessing IPs. Users can operate via a simple and easy-to-use graphical interface, and improve the accuracy of analysis results by modifying configuration files.
- hary654321/webscan
- Webscan is a web scanning tool for security purposes, written in Go and using LevelDB. It includes features like directory traversal and log data management.
- hahwul/mad-metasploit
- Mad Metasploit is a collection of custom Metasploit modules, plugins, and resource scripts for various purposes such as auditing, exploitation, and resource scripts. It also features an archive function for easy updating and deleting of collected content. The project is available on Github and can be installed via multiple methods, including manual installation and integration into the Metasploit framework. Donations can be made via PayPal and Buy Me a Coffee.
- GhostTroops/scan4all
- Free cross-platform Web network ncat reverse shell tool, supporting multiple protocols and password brute force, fast scanning and smart password brute force features, including 23 different password brute force methods and 15000+ PoC detection capabilities.
- fozavci/metasploit-framework-with-viproy
- Metasploit security framework containing multiple modules and plugins, usable for penetration testing and exploit development.
- fofapro/vulfocus
- Vulfocus is a vulnerability integration platform that packs vulnerability environment Docker images, ready to use out of the box.
- ExpLangcn/NucleiTP
- NucleiTP is a full-network monitoring tool that performs automated security testing and risk assessment on network security through real-time updated PoCs, supporting multiple risk level classification storage.
- ExpLangcn/HwToolslibrary
- Contains a plugin directory and three files, providing vulnerability detection example codes, supporting AI-generated PoC plugins. Network security tool library.
- Esonhugh/Nuclei-Template-Backup
- Nuclei Templates is a community-curated list of templates for the nuclei engine to find security vulnerabilities in applications. It includes various templates provided by the team and contributed by the community. The project has an active community on Discord and Twitter, and welcomes contributions via pull requests or Github issues.
- Ershu1/2023_Hvv
- Collection of information related to HVV confrontation, including scanners, penetration testing tools, and scripts.
- edoardottt/missing-cve-nuclei-templates
- Weekly updated data on CVEs missing from the official nuclei templates repository. Sorted by vulnerability type and year, with counts and data links for each category. Helps security professionals build custom templates to handle missing CVEs and improve overall product security through penetration testing and vulnerability assessment.
- ed-red/redmc_custom_templates_nuclei
- A set of custom templates developed by the redmc team based on the Nuclei tool, used to discover vulnerabilities and misconfigurations in cloud environments.
- echohun/tools
- Security testing tool collection, including port scanning, subdomain collection, fingerprint collection, vulnerability scanning, and brute force.
- e-m-b-a/emba
- EMBA is an open-source security scanner that performs static and dynamic analysis on firmware of embedded devices, identifying weaknesses and vulnerabilities. It generates web reports for further analysis and has system emulation and AI-assisted analysis options.
- DefectDojo/django-DefectDojo
- Django DefectDojo is an open-source security management tool that coordinates security testing, vulnerability tracking, deduplication, remediation, and reporting. Provides DevSecOps, ASPM (Application Security Posture Management), and vulnerability management solutions. The project includes executable files, directory structure, and README information.
- danielmiessler/SecLists
- SecLists collects various types of security testing lists, such as usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, etc., useful for security assessments.
- danielgottt/malware-detection-analytics
- This project, named detection-rules/analytics, provides some rules and analytics, including tools like YARA, Suricata, Sigma, Osquery, and LOLBAS, aimed at detecting network security threats.
- d3ckx1/Fvuln
- Automated security tool that probes alive IPs, open ports, web services, scans web vulnerabilities, performs brute force, and generates reports.
- cws6/POC-python
- Uses the pocsuite framework for vulnerability detection, including security test scripts for remote code execution and SQL injection in multiple CMS systems and web servers.
- CVEDB/Poc-Git
- Provides publicly available exploit codes from the past two decades, supports browsing and searching for specific products or versions, and offers functionality to create searchable HTML tables.
- coffee727/VE
- VulApps is a Docker image library collecting various vulnerability environments and security tool environments, convenient for security testing and learning.
- CLincat/vulcat
- Vulcat is an open-source web application security scanning tool that can detect various web vulnerabilities and provide detailed reports and solutions.
- Ciyfly/woodpecker
- Woodpecker is a security tool implemented in Go, supporting PoC scanning validators for Xray nuclei YAML and Go code. Woodpecker has a web backend mode and command-line mode, and supports progress bar data, yaml/go poc import to db scripts, etc.
- chaitin/xray_blog
- Provides article categorization, tags, and archiving functions, with good security.
- chaitin/xray
- xray is a powerful security assessment tool that provides multiple plugins for detecting common network security issues, such as XSS, SQL injection, command/code injection, weak passwords, etc. It also supports custom PoCs and includes some commonly used PoCs for easy user extension. xray's detection modules continuously add new plugins covering more vulnerability types. In addition to basic web scanning, xray supports advanced features like file upload and weak password detection. Using xray can quickly and efficiently discover potential security risks, making it very practical for network administrators and security engineers.
- chainreactors/picker
- Open-source tool that transforms GitHub repositories into private communities, supporting authentication and permission control.
- CERT-Polska/Artemis
- Artemis is a modular network reconnaissance tool and vulnerability scanner built on Karton, used for checking website security and generating easy-to-read security improvement messages. Initiated by the KN Cyber science club at Warsaw University of Technology and maintained by CERT Polska.
- cckuailong/reapoc
- Reapoc is an open-source security vulnerability range repository containing multiple PoCs and vulnerability targets, supporting frameworks like pocsploit, Nuclei, xray, pocsuite3, goby, and provides yearly vulnerability count statistics and directory lists for each year.
- capiton0/templates
- An automated penetration testing template project based on nuclei, including fingerprint recognition, vulnerability scanning, asset collection, and provides detailed usage documentation and tutorials.
- C0reL0ader/EaST
- EaST Framework is an open-source penetration testing framework containing multiple network attack tools and modules, characterized by high security, usability, extensibility, and cross-platform support.
- c0py7hat/POC-EXP
- POC-EXP is a collection of security tools containing various exploit codes and tools, suitable for security research and testing.
- brianwrf/hackUtils
- Tool kit for penetration testing and network security research based on Beautiful Soup, including multiple remote code execution exploit modules like Joomla, Apache Shiro, etc.
- barrracud4/image-upload-exploits
- Image Upload Exploits is a Github project containing old image exploits for known vulnerabilities in image processors.
- baidu-security/app-env-docker
- Application test environment built on Docker, can verify protection effects and supplement vulnerability descriptions, supports web vulnerability scanning and OpenRASP vulnerability testing, automatically forwards requests via socks5 proxy, more secure than modifying DNS.
- baboshute/baboshute.github.io
- Knowledge base integrating multiple vulnerability databases, providing vulnerabilities in OA, CMS, development frameworks, etc., supports Docker deployment.
- Arvinthksrct/alltemplate
- 3CX Phone Management Console is a tool for managing and configuring 3CX business phone systems, providing a visual interface, user management, grouping, and permission settings, while also featuring authentication and authorization mechanisms to enhance system security.
- aquasecuritySAglobalSSCS/insecure-bank
- Web application for testing security vulnerabilities, running on Tomcat or Docker, with hardcoded login credentials.
- aquasecurity/vuln-list-reserve
- Vuln-list-reserve is a backup repository for storing vulnerability lists when the vuln-list website is inaccessible.
- apache/solr-site
- This project is the source code repository for the Apache Solr website, using Markdown syntax and the Pelican tool to generate static web pages, and automatically building and previewing via ASF Buildbot. Editing is recommended via local build and preview, using ./build.sh -l for live preview. Python 3.5+ is recommended and dependencies should be installed using pip. To manually install Pelican, use pip install -r requirements.txt. It is recommended to create a virtual Python environment to avoid conflicts.
- anasbousselham/fortiscan
- Fortiscan is an exploitation tool targeting FortiGate SSL-VPN vulnerabilities, can be used to check if a device is vulnerable and supports obtaining device plaintext credentials.
- AmyangXYZ/AssassinGo
- AssassinGo is an extensible information gathering and vulnerability scanning framework supporting WebSocket Web GUI, with multiple features such as getting security headers, bypassing CloudFlare, detecting CMS versions, honeypot detection, port scanning, traceroute and marking subdomains on Google Maps, directory scanning and site map, Whois lookup, crawling parameterized URLs, basic SQLi check, basic XSS check, intruder, SSH Bruter, Google-Hacking with Headless-Chrome, friendly PoC interface and WebSocket Web GUI. It is licensed under MIT.
- amcai/myscan
- Python3-based security tool that uses Burpsuite and Redis to build a passive scanner, capable of detecting various security vulnerabilities in networks.
- ambionics/phpggc
- PHPGGC is a library of unserialize() payloads along with tools to generate them from the command line or programmatically. It can be considered as a PHP equivalent of ysoserial for PHP.
- Alfresco/SearchServices
- Alfresco Search Services source code repository, providing search capabilities, supporting Solr core functionality, usable for Alfresco Content Services.
- al0ne/suricata-rules
- Suricata-rules is a GitHub project for collecting and sharing high-quality Suricata IDS rules, aiming to provide network security protection.
- adminlove520/Nuclei_Online
- An open-source tool for network security scanning, supporting online execution and local templates, providing rich vulnerability detection functions.
- adampielak/nuclei-templates
- Security-related YAML files on GitHub, can configure tools and systems to enhance security.
- 78778443/QingScan
- QingScan is a security scanning tool that can automatically invoke various scanners to scan targets and display results centrally, convenient for user management and analysis.
- 2lambda123/AttackDetection
- Suricata PT Open Ruleset is a project containing network-layer attack and malicious activity detection rules, PoC exploits, and sample files. It includes a portion of rules for detecting TLS communication, requiring parameter settings in the suricata.yaml configuration file to activate. The project is maintained by the Attack Detection Team, who are dedicated to finding new vulnerabilities and 0-days and creating PoC exploits to understand how these vulnerabilities work and how related attacks can be detected at the network layer.
- 20142995/pocsuite3
- Open-source security toolkit containing a large number of Python scripts for collecting and testing network security-related vulnerabilities, supporting multiple common vulnerability types such as SQL injection, remote code execution, file upload, etc.
- 0x727/FingerprintHub
- Security fingerprint library, containing fingerprint information for Apache Shiro components, supports custom requests, automatic updating of fingerprint library.# Vulnerability Discovery and Testing
- zeroc00I/AllVideoPocsFromHackerOne
- Collects hacker zero-day reports and downloads all JSON files for searching, aiming to classify vulnerabilities by technique.
- wy876/POC
- Vulnerability collection, 2023 vulnerability information, providing EXP and POC.
- wwl012345/Vuln-List
- Vuln-List is a project that collects vulnerabilities of various common frameworks, providing detailed vulnerability descriptions, affected versions, POC/EXP, etc., making it easy for users to quickly find and exploit vulnerabilities.
- wooluo/POC
- A security research project that collects known vulnerability POCs, providing multiple POCs and vulnerability testing tools, along with related references and online verification services.
- Viralmaniar/BigBountyRecon
- Uses Google dorks and open-source tools for initial reconnaissance of target organizations, applying 58 techniques to gather information and estimate the target's security maturity level.
- Veraxy00/SkywalkingRCE-vul
- This project is a reproduction and exploitation example of the Apache SkyWalking remote code execution vulnerability, which has an encoding issue that could lead to arbitrary code execution.
- v1cker/kekescan
- kekescan is a comprehensive security scanning tool that includes multiple modules for web, bug, and file scanning, designed to discover vulnerabilities and improve system security.
- uboolean/exploitdb
- The official Git repository of the Exploit Database, containing the latest vulnerabilities and exploit code, and providing the SearchSploit tool for searching. Additionally, it includes executable file lists and other resources.
- trickest/cve
- CVE PoC provides all publicly available vulnerability proof-of-concept examples from the past nearly 20 years, with automatic updates and filtering capabilities.
- TobinShields/qdPM9.1_Exploit
- Exploits vulnerability CVE-2020-7246 by uploading a user photo with malicious code to achieve remote code execution (RCE).
- threedr3am/learnjavabug
- This project contains multiple submodules that record and analyze vulnerabilities in common frameworks or libraries such as Fastjson, Jackson, Dubbo, Apache CXF, Spring, Tomcat, Apache POI, etc., and provides example code for exploiting these vulnerabilities for various attack methods including RCE, SSRF, DoS, information leakage, etc.
- TheMirkin/CVE-List-Public-Exploits
- Contains CVE list and exploits folder, providing exploit tools for various public CVE vulnerabilities.
- tenable/poc
- Tenable's vulnerability exploit code repository, containing exploit code for multiple vendor products, usable for vulnerability discovery and testing.
- STMCyber/CVEs
- STM Cyber Proof-of-Concept exploits library, a collection of PoC exploits for publicly disclosed vulnerabilities in various software products.
- SleepingBag945/dddd
- Supports multiple input formats, active/passive fingerprint recognition, supply chain vulnerability detection tool.
- SkyBelll/CVE-PoC
- Provides publicly available proof-of-concept code for vulnerabilities from the past nearly four years, sorted by CVSS score. Users can search for specific products and versions to find related vulnerability information and generate easy-to-read markdown files. Additionally, the project offers automated processes to filter out false results and generate GitHub badges.
- shadowsock5/Poc
- Information on various open-source software and their exploit methods, covering multiple fields, suitable for security researchers and penetration testers.
- secrove/Vulnerabilities
- This project contains multiple exploit codes and related information for Oracle Weblogic and Spring, including but not limited to CVE-2016-0572, CVE-2017-10137, etc., with certain security research value.
- s7ck-Team/exploit-db
- Exploit-db is a security project containing various exploit tools, aiming to provide the latest security threat information and solutions.
- RhinoSecurityLabs/CVEs
- CVE vulnerability PoC attack script library, covering various types of vulnerabilities from local privilege escalation to remote code execution.
- redteam-project/exploit-curation
- LEM-curation collects and manages the exploit database used by the LEM tool, for vulnerability discovery and testing.
- rbowes-r7/refreshing-soap-exploit
- This project is a PoC tool for the F5 Big-IP security vulnerability CVE-2022-41622, which causes cross-site request forgery in the SOAP interface, allowing an attacker to execute any supported SOAP request using an authenticated user's session. The project provides a script for generating malicious XML templates and examples of important SOAP WSDL files.
- PortSwigger/BChecks
- Provides Burp Suite Professional users with multiple types of vulnerability detection plugins, including blind SSRF, exposed git directory, leaked AWS tokens, log4Shell, server-side prototype pollution, suspicious input transformation, etc., along with examples and other useful tools.
- Phuong39/2022-HW-POC
- Collects POC codes for various open-source tools and libraries, for security research and evaluation. Supports various attack methods such as SQL injection, remote code execution, etc.
- p0dalirius/CVE-2022-21907-http.sys
- This project contains code to demonstrate a security vulnerability in the Windows OS HTTP.sys driver. This vulnerability allows an attacker to execute arbitrary code on a Windows server after sending a specific type of HTTP request. The project includes executables and other resources related to the vulnerability.
- Ostorlab/known_exploited_vulnerbilities_detectors
- A security tool that detects known exploited vulnerabilities, supports scanning IP addresses, domain names, and links, can work with tools like subfinder or dnsx to scan all subdomains, and has implemented detection functions for some CVE IDs.
- ohnonoyesyes/CVE-2023-29084
- Command injection vulnerability PoC for ManageEngine ADManager Plus.
- NoorahSmith/Exploit-DB-offsec
- The official Git repository of the Exploit Database, containing the latest vulnerabilities and exploit code. Provides the SearchSploit tool for searching.
- noname1007/vulhub
- Vulhub is an open-source collection of pre-built vulnerable Docker environments, usable for vulnerability discovery and testing.
- nomi-sec/PoC-in-GitHub
- This project is a collection of PoCs (Proof of Concepts), containing various vulnerability and attack code examples, including but not limited to CVE-2023-0045, CVE-2023-0099, CVE-2023-0156, CVE-2023-0157, and CVE-2023-0159, covering various security issues such as memory leaks, privilege escalation, file inclusion, and XSS attacks.
- MzzdToT/HAC_Bored_Writing
- This project contains various batch-scanning PoCs and EXPs for unauthorized access, RCE, file upload, SQL injection, information disclosure vulnerabilities. Additionally, it provides tracking updates for the latest PoCs and EXPs.
- migueltarga/CVE-2020-9380
- PoC IPTV Smarters Exploit, exploiting a vulnerability in the file includes/ajax-control.php to achieve remote code execution, with Python script and screenshot verification.
- LongWayHomie/CVE-2021-43936
- This project named 'CVE-2021-43936' contains exploit code and test results, can execute code remotely, posing a serious security risk. Use with caution.
- light-Life/BUG-Pocket
- Small vulnerability library, including FOFA syntax and batch scripts, for learning purposes only, strictly prohibited for illegal use.
- langsasec/hw2023-bigbang
- This project contains multiple subdirectories, can be used to research unauthorized access in WeCom (WeChat Work) and vulnerabilities in products and services of multiple well-known security vendors.
- lal0ne/vulnerability
- A tool for collecting, organizing, and modifying publicly available vulnerability PoCs from the internet, containing a large amount of product fingerprint information and search engine results.
- KiritoLoveAsuna/Exploits
- Contains self-written and collected various exploit codes, covering N-day and 0-day vulnerabilities.
- killvxk/POCS
- Contains PoC codes for different vulnerabilities, usable for vulnerability discovery and testing.
- kevinhous30/Vaultiris
- Automated CVE monitoring tool for PoC identification and vulnerability detail viewing.
- Kento-Sec/poc
- Security vulnerability detection scripts for multiple brands and models, suitable for security assessment and testing in the network security field.
- KayCHENvip/vulnerability-poc
- Contains vulnerability information for various open-source software and frameworks, usable for vulnerability discovery and testing.
- kailing0220/-T-
- Detection and exploitation tool for arbitrary file read vulnerability in Yonyou Changjietong T+, suitable for security assessment.
- jiayy/android_vuln_poc-exp
- This project contains some vulnerabilities discovered by the author, including CVEs related to Android, Linux, QEMU, and Mosec-2016.
- jas502n/CVE-2019-20197
- Nagios XI remote command execution vulnerability PoC.
- ishell/Exploits-Archives
- Contains various exploit codes from 2000 to 2013, suitable for security testing and defense.
- Immersive-Labs-Sec/CVE-2021-32648
- This project named 'CVE-2021-32648' contains PoC code to demonstrate the principle of the OctoberCMS authentication bypass vulnerability (CVE-2021-32648).
- hmoytx/WVS
- WVS is a CMS vulnerability scanning tool written in Python, including directory scanning, online identification, and providing PoCs for over 300 vulnerabilities.
- Hacker5preme/Exploits
- Contains various developed exploit programs, usable for vulnerability discovery and testing.
- h0tak88r/nuclei_templates
- This project named 'Vulnerable Web Applications List (VWAL)' contains a list of common web application vulnerabilities, helping security experts conduct penetration testing and security assessment.
- govbk/WIKI-POC-EXP
- WIKI-POC-EXP is a collection library containing various vulnerability PoCs and EXPs, aimed at helping security researchers with vulnerability detection and exploitation.
- gottburgm/Exploits
- Personally written Perl reproducer/example code, addressing security vulnerabilities.
- getdrive/PoC
- This project contains multiple exploitation examples for remote code execution vulnerabilities in various software systems, including products from well-known vendors such as F5 BIG-IP, Confluence, WS_FTP Server, TeamCity, SolarView Compact, VMware Aria Operations for Networks, etc., with CVSSv3 scores of 9.8 or higher, extremely severe.
- expzhizhuo/cve_info_data
- This project named cve_info_data contains vulnerability resources for various IoT devices, including but not limited to routers, network devices, cameras, etc., and provides ways to obtain data from major platform vendors and links. It is mainly used for learning and consulting these vulnerability information to help users understand and fix potential security risks.
- ErYao7/YamlRepository
- YamlRepository is a GitHub project containing two subdirectories, Poc and finger, for storing YAML or YML format exploit codes (POC) and fingerprints.
- Doctype02/exploitdb
- ExploitDB is a Git repository containing various exploits, shellcode, and vulnerability-related articles. It is updated daily and provides a SearchSploit tool for content searching. This project is licensed under the GNU General Public License v2.0.
- DawnFlame/POChouse
- Includes various high-risk vulnerabilities that can achieve Getshell and related application Getshell techniques, one-click verification, supports batch verification, provides Metasploit and jar packages for exploiting vulnerabilities, as well as Python scripts.
- daffainfo/AllAboutBugBounty
- Collects various vulnerability information and bypass techniques, including file upload, cross-site scripting, denial of service attacks, etc.
- D-Haiming/gobypoc
- This project provides information on security vulnerabilities and weaknesses in various open-source software, helping users with vulnerability discovery and testing.
- CVEProject/cvelistV5
- This project provides a list of all CVE records identified and reported to the CVE program, and offers the ability to download these records in CVE JSON 5.0 format. Users can search, download, and use the content in this repository according to the CVE program's terms of service. Additionally, the project contains all versions of current CVE records and provides baseline and hourly update ZIP files and release notes. Users can obtain these versions by cloning the repository or accessing the published pages on GitHub.
- CVEProject/cvelist
- A Git pilot project for public vulnerability information, storing CVE lists in CVE JSON format and automatically updating, usable for vulnerability discovery and testing.
- CVEProject/cve-reference-ingest-data
- This project named cve-reference-ingest-data aims to provide security vulnerability information by reading and parsing CVE references.
- Cuerz/PoC-ExP
- Includes various network security vulnerability exploit codes, providing learning and research resources, but strictly prohibited for illegal purposes.
- cqr-cryeye-forks/goby-pocs
- This project contains multiple security vulnerabilities and backdoors for open-source software, including but not limited to SQL injection, file read privilege escalation, weak passwords, command execution, etc.
- coffeehb/Some-PoC-oR-ExP
- This project collects various vulnerability PoCs and EXPs, including exploit codes for common web applications such as Apache, Django, MySQL, etc.
- cckuailong/vulbase
- Vulbase is a vulnerability library collection, runs via Docker, supports basic auth authentication, including Peiqi library and WGPsec Wiki.
- boy-hack/airbug
- A long-term open security vulnerability collection repository, supports vulnerability PoC submission and online verification, suitable for product testing and evaluation.
- BLACKHAT-SSG/CVEs
- Based on the 'Trickest' workflow, collects and splits publicly available vulnerability (CVE) PoCs by year.
- bitfront-se/vuln-list-temp
- Vuln-list-temp is a GitHub project that organizes vulnerability information from various sources (including CWE, GHSA, Go, NVD, and OSV). It provides developers and security professionals with a comprehensive view of known vulnerabilities to improve their security posture.
- Balzu/PyPhish
- PyPhish is a Python framework for simulating phishing attacks, including email templates and command-and-control server, to assess an organization's employee awareness of cybersecurity.
- Axx8/CVE-2022-24112
- Exploits the batch request functionality of Apache APISIX for remote code execution (RCE), providing Python script and command examples.
- Ares-X/VulWiki
- Based on the Zero Group public vulnerability library security project, covering web security, system security, and IoT security vulnerabilities.
- aquasecurity/vuln-list-nvd
- Python script utilizing the NVD vulnerability database to collect and display security vulnerability information on the system.
- anvbis/chrome_v8_ndays
- Chrome browser multi-version, different types of vulnerability exploit code examples.
- Alucard0x1/CVE-2023-30777
- This project is a PoC generator for a reflected cross-site scripting (XSS) vulnerability in the WordPress plugin Advanced Custom Fields, usable for testing if the target system is vulnerable.
- 4ra1n/super-xray
- Super X-ray is a GUI tool based on the xray vulnerability scanner, providing a friendly user interface to make it easier for beginners. It includes various functions such as subdomain scanning, reverse proxy, etc., supports Chinese and English, making it easy to find and run PoCs. It also integrates rad linkage and supports multiple scanning modes.
- 1979139113/0day-today-exploits
- This project provides a large number of exploit files for vulnerability discovery and testing.
- 1120362990/vulnerability-list
- Vulnerability quick detection tool, supports multiple common vulnerability detections, written in Python.
- 0xmaximus/Apache-Commons-Text-CVE-2022-42889
- Detection and exploitation tool for Apache Commons Text vulnerability (CVE-2022-42889).
- 0x27/CiscoRV320Dump
- A collection of exploit tools for Cisco RV320 routers, including configuration and diagnostic log file leakage, decryption, and remote command execution, with corresponding exploit implementations.
Security Scanning and Detection
- u21h2/nacs
- nacs is a security scanner with functions such as host discovery, service scanning, PoC detection, database weak password brute force, and common intranet vulnerability exploitation. Users can use this tool by providing target IP or URL, passwords and other parameters, and can choose whether to perform brute force, PoC detection, etc.
Security Integration and Deployment
- TachiuLam/SeMF
- Enterprise intranet security management platform, including asset management, vulnerability management, account management, knowledge base management, and automated security scanning, for internal security management.
- naozibuhao/SecurityManageFramwork
- Enterprise intranet security management platform, including asset management, vulnerability management, account management, knowledge base management, and automated security scanning modules, applicable for enterprise internal security management.
Vulnerability and Intelligence Libraries
- pan-unit42/iocs
- Collection of indicators related to Unit 42 public reports, containing IOC information for various malware and attacks, used for threat intelligence analysis in the security field.
- omarhashem123/Security-Research
- This project named 'CVE Vulnerability Database' contains information on multiple high-risk vulnerabilities, providing important reference value for network security protection.
- nomi-sec/NVD-Database
- Contains vulnerability databases from 1999 to 2023, used for vulnerability management and risk assessment in the security field.
- justakazh/CVE_Database
- Provides a list of Common Vulnerabilities and Exposures (CVE) from the National Vulnerability Database (NVD). Data in JSON format for easy integration and consumption.# Security Knowledge Base & Documentation
- nosafer/nosafer.github.io
- VulWiki is a security knowledge base based on an open-source vulnerability database, covering various web applications and system security vulnerabilities, and provides detailed vulnerability analysis and exploitation methods.
- Micr067/Vulnerability-Wiki
- A knowledge base that integrates multiple open-source vulnerability databases, supports multiple deployment methods, and includes the wooyun vulnerability database.
Open Source License