
Complete-google-dorks
Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

A collection of awesome security hardening guides, tools and other resources

Open-source vulnerability database aggregating CVE data from multiple sources with a web UI and API. Maps vulnerabilities to specific software…

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Web vulnerability scanner written in Python3

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Automated NoSQL database enumeration and web application exploitation tool.

A collection of web pages vulnerable to SQL injection flaws