
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Protect against malicious open source packages 🤖

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

A project security/vulnerability/risk scanning tool

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs,…

Apache Karaf XXE Vulnerability (CVE-2018-11788)

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574