function: vulnerability-scanning
447 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Z4nzu/hackingtool An all-in-one, menu-driven Python toolkit that aggregates 215 curated security testing tools across 21 categories such as recon, OSINT, web… | 77 | 79125 | active |
| KeygraphHQ/shannon Shannon is an open-source, autonomous AI pentester for web applications and APIs that runs locally from the command line. It analyzes sourc… | 84 | 47226 | active |
| Trivy Trivy is an all-in-one open-source security scanner that finds vulnerabilities (CVEs), IaC misconfigurations, secrets, and software license… | 98 | 37636 | stable |
| projectdiscovery/nuclei Nuclei is a fast, open-source vulnerability scanner built on a simple YAML-based template DSL, maintained by ProjectDiscovery. It uses a la… | 98 | 30855 | active |
| Harbor Harbor is an open source cloud native container registry that stores, signs, and scans container images and other OCI artifacts. It extends… | 96 | 29236 | stable |
| trufflesecurity/trufflehog TruffleHog is an open-source secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across Git reposi… | 95 | 27599 | active |
| MobSF/Mobile-Security-Framework-MobSF MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs stati… | 94 | 21650 | active |
| CISOfy/lynis Lynis is an open-source security auditing and hardening tool for UNIX-based systems including Linux, macOS, and BSD. It performs in-depth l… | 90 | 16239 | stable |
| zaproxy/zaproxy Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps du… | 78 | 15686 | stable |
| NVIDIA/SkillSpector SkillSpector is a security scanner for AI agent skills used by Claude Code, Codex CLI, Gemini CLI, and MCP-based agents. It detects vulnera… | 81 | 15011 | active |
| prowler-cloud/prowler Prowler is an open-source cloud security platform that performs security best-practice assessments, audits, continuous monitoring, hardenin… | 95 | 14687 | active |
| shadow1ng/fscan Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-pa… | 95 | 14450 | active |
| awslabs/git-secrets git-secrets is a command-line tool that scans git commits, commit messages, and merge histories for secrets and credentials, rejecting comm… | 51 | 13380 | stable |
| threat9/routersploit RouterSploit is an open-source exploitation framework dedicated to embedded devices like routers, modeled after Metasploit. It provides mod… | 59 | 13223 | active |
| anchore/grype Grype is an open-source vulnerability scanner for container images, filesystems, and SBOMs, written in Go by Anchore. It identifies known C… | 98 | 12789 | active |
| future-architect/vuls Vuls is an agent-less vulnerability scanner written in Go that detects CVEs on Linux, FreeBSD, Windows, macOS, containers, WordPress, progr… | 98 | 12243 | active |
| chaitin/xray xray is a security assessment tool from Chaitin that scans web applications for common vulnerabilities like XSS and SQL injection, supporti… | 23 | 11720 | active |
| kubescape/kubescape Kubescape is an open-source Kubernetes security platform (a CNCF incubating project) offering misconfiguration scanning, vulnerability asse… | 98 | 11692 | active |
| quay/clair Clair is an open-source service for static analysis of vulnerabilities in container images (OCI and Docker). It indexes image contents via … | 74 | 11052 | active |
| 1N3/Sn1per Sn1per is an open-source automated penetration testing and attack surface management platform that chains reconnaissance, scanning, exploit… | 63 | 11043 | active |
| google/osv-scanner OSV-Scanner is Google's official CLI and Go library frontend to the OSV.dev vulnerability database, scanning project dependencies across ma… | 99 | 10924 | active |
| sullo/nikto Nikto is a Perl-based command-line web server scanner that tests servers for dangerous files, outdated software, misconfigurations, and kno… | 89 | 10684 | active |
| projectdiscovery/httpx httpx is a fast, multi-purpose HTTP toolkit written in Go that runs multiple probes (status codes, titles, TLS certificates, tech detection… | 93 | 10322 | active |
| openai/codex-security OpenAI's Codex Security is a CLI and TypeScript SDK that uses AI to find, validate, and fix security vulnerabilities in codebases. It suppo… | 80 | 10202 | active |
| CodeQL CodeQL is a semantic code analysis engine that treats code as a queryable database, letting you write queries to find security vulnerabilit… | 77 | 10016 | active |
| wpscanteam/wpscan WPScan is a black-box WordPress security scanner written in Ruby, used by security professionals and site maintainers to audit WordPress in… | 93 | 9740 | active |
| docker/docker-bench-security Docker Bench for Security is a shell script that automates checks of Docker hosts and containers against the CIS Docker Benchmark best prac… | 61 | 9693 | active |
| testssl/testssl.sh testssl.sh is a free, bash-based command line tool that checks any server's service on any port for TLS/SSL cipher, protocol, and cryptogra… | 88 | 9181 | active |
| NVIDIA/garak garak is a command-line LLM vulnerability scanner that probes large language models for failures like hallucination, data leakage, prompt i… | 91 | 9033 | active |
| frohoff/ysoserial ysoserial is a proof-of-concept command-line tool that generates serialized Java payloads exploiting unsafe object deserialization using ga… | 48 | 9033 | active |
| bridgecrewio/checkov Checkov is a static code analysis tool for infrastructure as code (Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, and more) that … | 95 | 8973 | stable |
| securego/gosec gosec is a security scanner for Go source code that inspects the AST and SSA representations to detect common security problems. It include… | 99 | 8933 | active |
| yogeshojha/rengine reNgine is a self-hosted automated web reconnaissance and vulnerability scanning framework with configurable recon engines, data correlatio… | 64 | 8795 | active |
| Tsunami Security Scanner Tsunami is a general-purpose network security scanner from Google that detects high-severity vulnerabilities with high confidence. It relie… | 74 | 8606 | active |
| PyCQA/bandit Bandit is a security-oriented static analysis tool that finds common security issues in Python code. It parses each file into an AST, runs … | 86 | 8242 | active |
| aquasecurity/kube-bench kube-bench is a Go-based tool that checks whether Kubernetes clusters are deployed securely by running the checks documented in the CIS Kub… | 98 | 8155 | active |
| vercel-labs/deepsec Deepsec is an open-source, agent-powered vulnerability scanner that runs AI coding agents over your entire existing codebase to find hard-t… | 58 | 7828 | active |
| Scout Suite Scout Suite is an open source multi-cloud security auditing tool that assesses the security posture of cloud environments. It gathers confi… | 42 | 7801 | stable |
| yaklang/yakit Yakit is an all-in-one interactive application security testing platform built as a GUI client for the Yaklang security DSL engine over gRP… | 95 | 7700 | active |
| dependency-check/DependencyCheck OWASP Dependency-Check is a Software Composition Analysis (SCA) tool that identifies publicly disclosed vulnerabilities (CVEs) in a project… | 98 | 7671 | active |
| presidentbeef/brakeman Brakeman is a free, open-source static analysis security scanner built specifically for Ruby on Rails applications. It analyzes Rails sourc… | 93 | 7262 | stable |
| apache/caldera Apache Caldera is a cybersecurity platform for automated adversary emulation built on the MITRE ATT&CK framework. It provides an asynchrono… | 79 | 7213 | active |
| ayoubfaouzi/al-khaser Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debu… | 73 | 7108 | active |
| lintsinghua/DeepAudit DeepAudit is an open-source multi-agent AI system for automated code vulnerability discovery and security auditing, with a React frontend a… | 72 | 6905 | active |
| ticarpi/jwt_tool A Python command-line toolkit for validating, forging, scanning, and tampering with JSON Web Tokens (JWTs). It automates checks for known J… | 31 | 6754 | active |
| infobyte/faraday Faraday is an open-source vulnerability management platform that aggregates, normalizes, and deduplicates findings from over 90 security to… | 98 | 6695 | active |
| The-Z-Labs/linux-exploit-suggester A shell-based auditing tool that assesses a Linux system's exposure to publicly known kernel privilege escalation exploits based on kernel … | 65 | 6593 | active |
| zizmorcore/zizmor zizmor is a static analysis tool for CI/CD configurations, primarily GitHub Actions workflows, as well as Dependabot and pre-commit configs… | 84 | 6394 | active |
| crytic/slither Slither is a Python-based static analysis framework for Solidity and Vyper smart contracts. It runs vulnerability detectors, prints contrac… | 94 | 6352 | active |
| dwisiswant0/apkleaks APKLeaks is a Python CLI tool that decompiles Android APK files with jadx and scans them for URIs, endpoints, and hardcoded secrets using r… | 39 | 6275 | active |
| infinition/Bjorn Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers … | 63 | 6252 | active |
| k8gege/K8tools K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege … | 34 | 6203 | active |
| gitleaks/gitleaks Gitleaks is an open-source CLI tool for detecting secrets like passwords, API keys, and tokens in git repositories, files, directories, and… | 91 | 28965 | maintenance |
| GhostTroops/scan4all scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I… | 23 | 6170 | active |
| anthropics/claude-code-security-review A GitHub Action that uses Anthropic's Claude to perform AI-powered security reviews of pull requests, analyzing code diffs for vulnerabilit… | 48 | 6093 | active |
| Tencent/AI-Infra-Guard Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate… | 88 | 5984 | active |
| commixproject/commix Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of … | 75 | 5824 | active |
| ossf/scorecard OpenSSF Scorecard is an automated tool that scores open source projects on security best practices through a series of checks. It can be ru… | 88 | 5653 | active |
| snyk/cli The Snyk CLI is a command-line tool that scans projects for security vulnerabilities across open-source dependencies, application code, con… | 99 | 5649 | active |
| google/clusterfuzz ClusterFuzz is Google's scalable fuzzing infrastructure that finds security and stability bugs in software, serving as the backend for OSS-… | 95 | 5597 | active |
| OWASP/Nettacker OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scann… | 88 | 5535 | active |
| Ladon Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset di… | 29 | 5320 | active |
| ThreatMapper Deepfence ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts threats in production cloud, Kuber… | 84 | 5318 | active |
| hahwul/dalfox Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of r… | 98 | 5256 | active |
| V4bel/dirtyfrag Dirty Frag is a proof-of-concept Linux kernel local privilege escalation exploit written in C. It chains the xfrm-ESP (CVE-2026-43284) and … | 50 | 4990 | active |
| perplexityai/bumblebee Bumblebee is a read-only Go CLI that scans developer endpoints for on-disk package, extension, and developer-tool metadata (lockfiles, pack… | 76 | 4975 | active |
| bitsadmin/wesng WES-NG is a Python command-line tool that parses Windows `systeminfo` output (or missing KB listings) and cross-references it against a reg… | 76 | 4923 | active |
| charles2gan/GDA-android-reversing-Tool GDA (GJoy Dex Analyzer) is a fast, native C++ Dalvik bytecode decompiler and reverse analysis platform for Android binaries such as APK, DE… | 70 | 4818 | active |
| greenbone/openvas-scanner OpenVAS Scanner is the scan engine of the Greenbone Community Edition, executing a continuously updated feed of vulnerability tests against… | 95 | 4796 | active |
| cdk-team/CDK CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environment… | 70 | 4740 | active |
| Yelp/detect-secrets detect-secrets is a Python CLI tool from Yelp that detects secrets (API keys, passwords, tokens) in codebases using regex and entropy heuri… | 57 | 4629 | active |
| Awarexone/Agentic-Bug-Hunter An AI-powered bug bounty hunting toolkit that automates reconnaissance, vulnerability testing, finding validation, and report generation fo… | 77 | 4464 | active |
| zan8in/afrog afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug b… | 96 | 4372 | active |
| microsoft/PyRIT PyRIT is Microsoft's open-source Python framework for identifying security and safety risks in generative AI systems. It provides automatio… | 88 | 4361 | active |
| jtesta/ssh-audit ssh-audit is a Python CLI tool that audits SSH server and client configurations, analyzing banners, key exchange, encryption, MAC, and comp… | 82 | 4280 | active |
| ConsenSysDiligence/mythril Mythril is a symbolic-execution-based security analysis tool for EVM bytecode that detects vulnerabilities in Ethereum and other EVM-compat… | 58 | 4265 | active |
| TideSec/TscanPlus TscanPlus is a comprehensive network security detection and operations tool for rapid asset discovery, identification, and vulnerability de… | 82 | 4257 | active |
| RetireJS/retire.js Retire.js is a scanner that detects the use of JavaScript libraries and Node.js modules with known vulnerabilities, available as a CLI scan… | 99 | 4161 | active |
| DependencyTrack/dependency-track OWASP Dependency-Track is an open-source component analysis platform that ingests CycloneDX SBOMs to continuously identify vulnerabilities,… | 99 | 4145 | active |
| theori-io/copy-fail-CVE-2026-31431 A proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation bug in the authencesn cryptographic template that … | 50 | 4049 | active |
| speed47/spectre-meltdown-checker A self-contained shell script that checks Linux and BSD systems for vulnerability to transient execution CPU vulnerabilities such as Spectr… | 94 | 3947 | active |
| itm4n/PrivescCheck A PowerShell enumeration script that identifies common Windows privilege escalation vulnerabilities and misconfigurations. It also collects… | 98 | 3928 | active |
| Pocsuite pocsuite3 is an open-source remote vulnerability testing and proof-of-concept development framework by Knownsec's 404 Team. It provides a P… | 27 | 3872 | active |
| trimstray/htrace.sh htrace.sh is a shell-script CLI that combines HTTP/HTTPS request troubleshooting (redirect tracing, headers, body, SSL parameters, custom m… | 32 | 3860 | active |
| pwntester/ysoserial.net ysoserial.net is a proof-of-concept command-line tool that generates deserialization payloads exploiting unsafe .NET object deserialization… | 62 | 3782 | active |
| scipag/vulscan Vulscan is an Nmap NSE script that turns Nmap into a vulnerability scanner by matching version-detected services against offline vulnerabil… | 52 | 3780 | active |
| nabla-c0d3/sslyze SSLyze is a fast SSL/TLS scanning tool and Python library that analyzes a server's TLS configuration, including certificates, cipher suites… | 83 | 3775 | stable |
| aquasecurity/cloudsploit CloudSploit by Aqua is an open-source Cloud Security Posture Management (CSPM) tool that scans cloud infrastructure accounts for misconfigu… | 72 | 3768 | active |
| edoardottt/cariddi Cariddi is a fast command-line web crawler written in Go that takes a list of domains, crawls URLs, and scans for endpoints, secrets, API k… | 84 | 3753 | active |
| ly4k/Certipy Certipy is a Python CLI toolkit for enumerating and abusing Active Directory Certificate Services (AD CS) misconfigurations. It detects and… | 94 | 3643 | active |
| e-m-b-a/emba EMBA is an open-source firmware security analyzer for embedded Linux devices, written in Bash. It automates firmware extraction, static and… | 93 | 3614 | active |
| s0md3v/XSStrike XSStrike is a Python command-line Cross Site Scripting (XSS) detection suite that uses hand-written HTML/JavaScript parsers, context analys… | 31 | 15151 | maintenance |
| vulnersCom/nmap-vulners A collection of Nmap NSE scripts that enrich service scans with CVEs, CVSS scores and known exploits from the Vulners database. It fingerpr… | 98 | 3415 | active |
| google/honggfuzz Honggfuzz is a security-oriented, feedback-driven evolutionary fuzzer that uses software and hardware code coverage to discover bugs in bin… | 62 | 3376 | active |
| almandin/fuxploider Fuxploider is an open-source penetration testing tool that automates detection and exploitation of file upload form vulnerabilities. It ide… | 32 | 3328 | active |
| chipsec/chipsec CHIPSEC is a Python framework for analyzing the security of PC platforms, including hardware, system firmware (BIOS/UEFI), and platform com… | 98 | 3295 | active |
| goodwithtech/dockle Dockle is a container image linter written in Go that checks Docker images against security best practices and CIS Benchmarks. It runs as a… | 66 | 3292 | active |
| techgaun/github-dorks A Python CLI tool that automates GitHub code searches using a curated list of dorks to find leaked secrets like credentials, private keys, … | 43 | 3271 | active |
| rtcatc/Packer-Fuzzer Packer Fuzzer is a Python-based security scanner that targets websites built with JavaScript module bundlers like Webpack. It automatically… | 23 | 3249 | active |
| sa7mon/S3Scanner A multi-threaded CLI tool written in Go that scans for misconfigured (open) S3 buckets across AWS and other S3-compatible providers like GC… | 77 | 3165 | active |
page 1 / 5 next →