
osv-scanner
Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Proof-of-concept exploit for Jenkins Templating Engine plugin sandbox bypass (CVE-2025-31722) enabling remote code execution via malicious Groovy…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

A wrapper around grep, to help you grep for things

My experiments in weaponizing Nim (https://nim-lang.org/)

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

UNIX-like reverse engineering framework and command-line toolset

Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.

Main repo for hosting release binaries

Community curated list of templates for the nuclei engine to find security vulnerabilities.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Ghidra is a software reverse engineering (SRE) framework

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.