
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24

🔍 Recon notes organizer for bug bounty hunters and CTF players — subdomains, ports, endpoints, vulns, all in one place.

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

A lightweight stdio-based MCP server for local file system operations — read, write, edit, search, exec for AI assistants. Specially optimized for…

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

Tools collection to explore CVE and theirs associated data.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

NotebookLM on steroids — purpose-built for security researchers.

SheetJS xlsx 0.18.5 fork with CVE-2023-30533 and CVE-2024-22363 fixes

Ralph Wiggum plugin implementation that works after the CVE-2025-54795 security patch

mcp-remote exposed to OS command injection

TinyXML 2.6.2 with fixes for CVE-2021-42260 and CVE-2023-34194

A plugin for DataSurgeon that Extracts CVE Numbers From Text (e.g: CVE-2021-56789)

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…