
awesome-security-hardening
A collection of awesome security hardening guides, tools and other resources

A collection of awesome security hardening guides, tools and other resources

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Automated Snyk vulnerability scanning for dependencies and Docker images in Bitbucket Pipelines, with severity thresholds and monitoring options.

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Jakarta EE and MicroProfile application server runtime for development and containerized deployments, supporting cloud-native middleware with…

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.

Test and validate Log4Shell (CVE-2021-44228) mitigation approaches with a sample vulnerable Log4j app, including JNDI exploitation, environment…

Deliberately vulnerable web application portal with a containerized backend, designed for practicing exploitation of CVE-2021-44228 and container…

Educational proof-of-concept exploit for CVE-2025-55182 targeting a React application, with Docker Compose environment for local testing and security…

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

Proof-of-concept exploit for CVE-2024-22262 in Spring applications, with a Dev Container environment for hands-on vulnerability exploration and…

Educational environment for LTAT.04.022 Homework 4.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Hands-on Dev Container environment for exploring CVE-2022-22970 with a vulnerable Spring application and proof-of-concept exploit code.

Dockerized vulnerable web application demonstrating the Log4j CVE-2021-44228 remote code execution vulnerability for educational exploitation and…

Dockerized proof-of-concept exploit for CVE-2019-13956, targeting a web application vulnerability accessible via HTTP on port 8090.