
osv-scanner
Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

Vulnerability scanner based on vulners.com audit API

Open-source, cross-platform, multi-purpose security auditing tool

A container analysis and exploitation tool for pentesters and engineers.

Docker images of Xpdf 4.04, vulnerable to CVE-2022-30524

System utility that identifies and restarts daemons using outdated libraries after package upgrades to maintain security. Supports containers and…

Suppress vulnerabilities applying Kubernetes context to scans

Give coding agents a disposable Linux VM, not your laptop

Shellshock exploit + vulnerable environment

PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Log4Shell (CVE-2021-44228) docker lab

Exploits CVE-2026-21005 by poisoning Docker Registry V2 Schema 1 manifests via unauthenticated pushes, enabling tag overwrite and supply-chain…

OWASP Honeypot, Automated Deception Framework.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability…