
osv.dev
Open source vulnerability DB and triage service.

Open source vulnerability DB and triage service.

Malicious package & supply-chain intelligence

VEX Repository Specification

This repository contains the scanner component for Greenbone Community Edition.

Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀

Microsoft Sentinel SIEM Log Source Analyzer

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Exploit for CVE-2022-25175 targeting Jenkins Pipeline: Multibranch plugin, enabling automated exploitation of a specific vulnerability in CI/CD…

Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit…

Simple and flexible tool for managing secrets

Linting tool for CloudFormation templates

Easily create full virtual machines that are sandboxed for development or computer use models.

Trivy example module for WordPress

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

K8S and Docker Vulnerability Check for CVE-2024-3094

Detection of the React Server Actions Exploit vector – CVE-2025-55182 / CVE-2025-66478

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…