


Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.


Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high…

Intel, AMD, VIA & Freescale Microcode Extraction Tool


Burp suite extension that lets you easily copy issues

Open-source vulnerability reporting tool for pentesters and security researchers. Manages finding templates, generates reports in HTML, PDF, CSV,…

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

openrisk is a tool that generates a risk score based on the results of a Nuclei scan.

Fuzzing framework written in python

Downloads and aggregates CVSS, EPSS, and CISA known exploited vulnerability data into unified JSON/CSV files and a SQLite database. Enriches…

GTK client of FaradaySEC

A Nmap XSL implementation with Bootstrap.

Modular credential validation framework with active and passive (regex-based) checking modes for penetration testers. Supports multiple services via…

Fast, simple library in Go to fetch CVEs from the National Vulnerability Database feeds

Burp Suite extension to track vulnerability assessment progress