function: vulnerability-scanning
447 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| xaitax/SploitScan SploitScan is a Python CLI cybersecurity utility that aggregates detailed vulnerability information for CVEs from sources like EPSS, CISA K… | 77 | 1379 | active |
| andresriancho/w3af w3af is an open source web application attack and audit framework that scans web applications for over 200 vulnerability types, including X… | 23 | 4900 | maintenance |
| fasnow/fine Fine is a Chinese-language cyberspace asset mapping and reconnaissance tool integrating FOFA, Hunter, Quake, ZoomEye, and Shodan APIs, plus… | 82 | 1366 | active |
| pypa/pip-audit pip-audit is a command-line tool that scans Python environments, requirements files, and dependency trees for packages with known security … | 83 | 1354 | active |
| fkie-cad/cwe_checker cwe_checker is a Rust-based suite of checks that detects common bug classes (CWEs) such as null pointer dereferences and buffer overflows i… | 67 | 1352 | active |
| moyuwa/ApkCheckPack A Go-based CLI tool that detects APK hardening/packing features from 40+ vendors, plus third-party SDKs, anti-environment checks (ROOT, emu… | 82 | 1347 | active |
| F6JO/RouteVulScan RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable … | 82 | 1334 | active |
| ZupIT/horusec Horusec is an open-source SAST (static application security testing) CLI that scans a project for vulnerabilities across many languages wit… | 67 | 1333 | active |
| silverhack/monkey365 Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects te… | 97 | 1332 | active |
| neuvector/neuvector NeuVector is an open-source full lifecycle container security platform providing vulnerability management and automated runtime security wi… | 94 | 1330 | active |
| test502git/awvs14-scan A Python batch-scanning script built on the Acunetix (AWVS) 14/15 API that automates bulk URL scanning with specialized templates for log4j… | 48 | 1318 | active |
| cseroad/Exp-Tools A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise softwa… | 21 | 1316 | active |
| HXSecurity/DongTai DongTai IAST is an open-source Interactive Application Security Testing platform that detects vulnerabilities in Java (and some Python) app… | 33 | 1312 | active |
| sulab999/AppMessenger AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (And… | 86 | 1308 | active |
| freelabz/secator secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm… | 93 | 1306 | active |
| 0xInfection/XSRFProbe XSRFProbe is a Python-based Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit. It crawls web applications, runs systema… | 82 | 1302 | stable |
| utkusen/sast-skills A collection of LLM agent skills that turn coding assistants like Claude Code, Codex, Opencode, and Cursor into a SAST (static application … | 49 | 1289 | active |
| bit4woo/Fiora Fiora is a graphical interface for the Nuclei vulnerability PoC framework, enabling quick PoC search and one-click execution of Nuclei scan… | 57 | 1282 | active |
| owasp-dep-scan/dep-scan OWASP dep-scan is a security and risk audit CLI tool that scans project dependencies in local repositories and container images for known C… | 97 | 1281 | active |
| larlarua/AutoCVE AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source… | 77 | 1280 | active |
| utkusen/promptmap promptmap2 is an automated prompt injection scanner for custom LLM applications, supporting white-box testing of system prompts and black-b… | 53 | 1254 | active |
| facebook/mariana-trench Mariana Trench is a security-focused static analysis platform for Android and Java applications, built by Meta on the SPARTA and Redex infr… | 77 | 1250 | active |
| lemono0/FastJsonParty FastJsonParty is a collection of Dockerized vulnerable environments covering multiple FastJson versions (1.2.47, 1.2.68, 1.2.80) for practi… | 28 | 1246 | active |
| PortSwigger/http-request-smuggler A Burp Suite extension that automatically detects and exploits HTTP Request Smuggling vulnerabilities, including HTTP/1.1 CL.TE/TE.CL desyn… | 76 | 1236 | active |
| bitquark/shortscan Shortscan is a Go CLI tool that enumerates files with short (8.3) filenames on IIS web servers and attempts to recover their full filenames… | 29 | 1215 | active |
| mongodb/kingfisher Kingfisher is an open-source, Rust-based secret scanner that detects leaked credentials in code, Git history, cloud storage, and developer … | 82 | 1214 | active |
| strozfriedberg/Windows-Exploit-Suggester A Python CLI tool that compares a Windows host's patch level (from systeminfo output) against the Microsoft security bulletin database to d… | 10 | 4229 | maintenance |
| CERT-Polska/Artemis Artemis is a modular, open-source vulnerability scanner developed by CERT Polska that checks website security at scale. It automatically ge… | 74 | 1204 | active |
| Hackmanit/Web-Cache-Vulnerability-Scanner A fast, Go-based CLI scanner for detecting web cache poisoning and web cache deception vulnerabilities. It supports many attack techniques,… | 60 | 1200 | active |
| ozguralp/gmapsapiscanner A Python CLI tool that tests whether a leaked or discovered Google Maps API key is vulnerable to unauthorized usage across many Google Maps… | 70 | 1198 | active |
| niudaii/zpscan zpscan is a Go-based command-line information gathering and reconnaissance tool for security assessments. It bundles subdomain enumeration,… | 23 | 1196 | active |
| DataDog/guarddog GuardDog is a CLI tool from Datadog that identifies malicious packages on PyPI, npm, Go modules, Rust crates, RubyGems, GitHub Actions, and… | 99 | 1194 | active |
| cloudflare/flan Flan Scan is a lightweight network vulnerability scanner from Cloudflare that wraps Nmap and the vulners script to detect open ports, servi… | 10 | 4166 | maintenance |
| chaitin/xpoc xpoc is a fast emergency-response vulnerability scanner from Chaitin's xray community, designed for supply chain vulnerability scanning. It… | 20 | 1186 | active |
| runZeroInc/sshamble SSHamble is a Go-based research and scanning tool for probing SSH server implementations. It enumerates SSH capabilities and tests for auth… | 68 | 1180 | active |
| jenish-sojitra/JSAnalyzer A Burp Suite extension written in Python (Jython) that performs static analysis on JavaScript files proxied through Burp. It extracts API e… | 44 | 1171 | active |
| mukul975/cve-mcp-server A Python-based Model Context Protocol (MCP) server that gives Claude ~28 security intelligence tools across 20+ APIs, including CVE lookup,… | 72 | 1164 | active |
| TongchengOpenSource/AppScan AppScan is a free, enterprise-grade automated privacy compliance detection tool for Android apps, based on dynamic analysis. It identifies … | 26 | 1128 | active |
| XmirrorSecurity/OpenSCA-cli OpenSCA-cli is an open-source Software Composition Analysis (SCA) command-line tool that scans projects to detect third-party open-source d… | 82 | 1125 | active |
| Adversis/tailsnitch Tailsnitch is a Go-based CLI security auditor for Tailscale configurations that scans a tailnet for 50+ misconfigurations, overly permissiv… | 74 | 1121 | active |
| CuriousLearnerDev/Online_tools A security tool marketplace application that lets users download, update, and automatically install a large catalog of penetration testing … | 96 | 1106 | active |
| safedep/vet vet is an open-source CLI tool for software composition analysis that scans open-source dependencies for malicious packages and vulnerabili… | 93 | 1103 | active |
| Loki LOKI is a free, open-source IOC and YARA scanner written in Python for triaging compromised systems. It detects indicators of compromise vi… | 51 | 3783 | maintenance |
| prompt-security/clawsec ClawSec is an AGPL-licensed suite of security skills for AI agent runtimes such as OpenClaw, NanoClaw, Hermes, and Picoclaw. It verifies sk… | 80 | 1097 | active |
| pashov/skills A collection of AI-powered Solidity security skills built by Pashov Audit Group, packaged for use with AI coding assistants like Claude Cod… | 75 | 1096 | active |
| Tuhinshubhra/RED_HAWK RED_HAWK is a PHP-based all-in-one reconnaissance and vulnerability scanning tool for websites. It performs information gathering (whois, D… | 32 | 3748 | maintenance |
| m-sec-org/EZ EZ is a cross-platform vulnerability scanner that combines information gathering, port scanning, service brute-forcing, URL crawling, finge… | 24 | 1078 | active |
| hahwul/jwt-hack jwt-hack is a fast, single-binary Rust CLI toolkit for testing, analyzing, and attacking JSON Web Tokens (JWT) and JWE tokens. It supports … | 91 | 1075 | active |
| qiwentaidi/Slack Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera… | 78 | 1073 | active |
| Lazarus-AI/clearwing Clearwing is a dual-mode autonomous offensive-security tool that combines a network-pentest ReAct agent with an LLM-driven source-code vuln… | 63 | 1063 | active |
| lachlan2k/React2Shell-CVE-2025-55182-original-poc A collection of original proof-of-concept exploits for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server … | 41 | 1059 | active |
| vigolium/vigolium Vigolium is a high-fidelity web vulnerability scanner written in Go that combines deterministic multi-phase scanning (317 modules for conte… | 82 | 1055 | active |
| ysrc/xunfeng Xunfeng is a self-hosted web application for rapid vulnerability emergency response and continuous scanning of enterprise internal networks… | 23 | 3597 | maintenance |
| NetSPI/PowerHuntShares PowerHuntShares is a PowerShell audit tool that inventories, analyzes, and reports excessive privileges on SMB share ACLs across Active Dir… | 53 | 1052 | active |
| robotshell/magicRecon MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumerati… | 23 | 1052 | active |
| cisco-ai-defense/mcp-scanner MCP Scanner is a Python tool and SDK from Cisco AI Defense that scans Model Context Protocol (MCP) servers, tools, prompts, and resources f… | 83 | 1051 | active |
| apkunpacker/MagiskDetection A curated collection of publicly available proof-of-concept Android apps that detect root, Magisk, Zygisk, and hooking frameworks like Frid… | 68 | 1050 | active |
| bountyyfi/lonkero Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules… | 73 | 1047 | active |
| splx-ai/agentic-radar Agentic Radar is an open-source security scanner that analyzes LLM agentic workflows built with popular frameworks (e.g., CrewAI, LangGraph… | 53 | 1043 | active |
| PhonePe/mantis Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level … | 67 | 1039 | active |
| zhzyker/vulmap Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them… | 23 | 3521 | maintenance |
| carlospolop/legion Legion is a Python-based automatic enumeration tool that orchestrates well-known open-source pentesting tools (nmap, hydra, metasploit) to … | 74 | 1032 | active |
| fullhunt/log4j-scan A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URL… | 23 | 3422 | maintenance |
| RuoJi6/audit-skills A lightweight Claude/Codex skill package for AI-assisted source code security auditing, covering Java, .NET, and PHP. It provides vulnerabi… | 73 | 1005 | active |
| ki9mu/ARL-plus-docker A Docker-based fork of ARL (Asset Reconnaissance Lighthouse) v2.6.2 that performs automated asset discovery and vulnerability scanning for … | 35 | 1005 | active |
| microsoft/DevSkim DevSkim is a Microsoft security linting framework consisting of IDE extensions, a .NET CLI, and a rule engine that flags security issues in… | 98 | 1004 | active |
| d78ui98/APKDeepLens APKDeepLens is a Python-based static analysis tool that decompiles Android APK files with JADX and scans them for security vulnerabilities … | 64 | 1004 | active |
| linkedin/qark QARK (Quick Android Review Kit) is a Python command-line tool from LinkedIn that scans Android applications, either as Java source code or … | 23 | 3382 | maintenance |
| codingo/NoSQLMap NoSQLMap is an open-source Python command-line tool that audits, automates injection attacks against, and exploits default configuration we… | 65 | 3345 | maintenance |
| s-rah/onionscan OnionScan is a free and open source Go CLI tool for investigating Tor hidden services (.onion sites) on the Dark Web. It scans sites for op… | 23 | 3290 | maintenance |
| arthepsy/ssh-audit ssh-audit is a dependency-free Python CLI tool that audits SSH servers by grabbing banners and enumerating key exchange, host key, encrypti… | 32 | 2995 | maintenance |
| andrewyng/openworker OpenWorker is an open-source desktop AI agent application that completes real work end-to-end — code security reviews with fix branches, cl… | 80 | 16241 | experimental |
| grayddq/GScan GScan is a Python-based CLI security tool that automates comprehensive Linux host security checks for incident response. It scans for backd… | 23 | 2826 | maintenance |
| shack2/SNETCracker A Windows GUI tool for auditing weak passwords across many network services such as SSH, RDP, SMB, MySQL, Redis, and FTP. It supports batch… | 23 | 2740 | maintenance |
| flipkart-incubator/Astra Astra is an automated REST API security testing tool from Flipkart that detects vulnerabilities like SQL injection, XSS, broken authenticat… | 32 | 2658 | maintenance |
| AlessandroZ/BeRoot BeRoot is a post-exploitation tool that checks common misconfigurations on Windows, Linux, and macOS hosts to identify potential privilege … | 23 | 2621 | maintenance |
| xoreaxeaxeax/rosenbridge Rosenbridge is a security research project that documents a hardware backdoor in some VIA C3 x86 processors, allowing userland code to bypa… | 32 | 2614 | maintenance |
| FiloSottile/Heartbleed A command-line tool and former web service for detecting the Heartbleed vulnerability (CVE-2014-0160) in TLS servers. Written in Go, it tes… | 32 | 2380 | maintenance |
| tr0uble-mAker/POC-bomber POC-bomber is a Python-based offensive security tool that bundles a large arsenal of high-impact POCs and EXPs (RCE, deserialization, file … | 23 | 2369 | maintenance |
| bugcrowd/HUNT HUNT Suite is a collection of Burp Suite and OWASP ZAP proxy extensions that identify common parameters vulnerable to vulnerability classes… | 67 | 2331 | maintenance |
| rabbitmask/WeblogicScan A one-click Python vulnerability scanner for Oracle WebLogic servers, covering nearly all historical WebLogic CVEs (SSRF, Java deserializat… | 32 | 2261 | maintenance |
| Ascotbe/Medusa Medusa is a self-hosted red team arsenal platform written in Python that bundles tools such as an XSS platform, collaborative platform, CVE… | 23 | 2235 | maintenance |
| HatBoy/Struts2-Scan A Python CLI tool that scans and exploits known Apache Struts2 vulnerabilities (S2-001 through S2-057) using publicly disclosed exploits. I… | 32 | 2220 | maintenance |
| praetorian-inc/gokart GoKart is a static analysis (SAST) tool for Go that detects vulnerabilities using SSA-form source-to-sink taint tracing. It reduces false p… | 10 | 2157 | maintenance |
| anouarbensaad/vulnx VulnX is a Python CLI tool that detects CMS types (WordPress, Joomla, Drupal, etc.), gathers target information like subdomains and DNS rec… | 23 | 2138 | maintenance |
| skavngr/rapidscan RapidScan is a Python CLI tool that automates web vulnerability scanning by orchestrating multiple security tools (nmap, nikto, wafw00f, ss… | 23 | 2128 | maintenance |
| firmadyne/firmadyne FIRMADYNE is an automated, scalable platform for emulating and dynamically analyzing Linux-based embedded firmware using QEMU with instrume… | 32 | 2102 | maintenance |
| TideSec/WDScanner WDScanner is a self-hosted distributed web vulnerability scanning platform written in PHP with Python backend workers. It combines customer… | 32 | 2100 | maintenance |
| iSafeBlue/TrackRay TrackRay (溯光) is an open-source penetration testing framework written in Java on SpringBoot that implements its own vulnerability scanning … | 23 | 2078 | maintenance |
| 0xn0ne/weblogicScanner A Python CLI vulnerability scanner for Oracle WebLogic servers that detects a wide range of known CVEs (2014-2020), including deserializati… | 32 | 2073 | maintenance |
| mozilla/cipherscan Cipherscan is a command-line tool that tests which SSL/TLS ciphersuites a target server supports and in what order, wrapping the openssl s_… | 44 | 1994 | maintenance |
| w-digital-scanner/w13scan W13Scan is an open-source Python3 web vulnerability scanner supporting both passive (proxy-based) and active scanning modes. It ships with … | 32 | 1946 | maintenance |
| Xyntax/POC-T POC-T is a Python 2.7 plugin-based concurrent framework for penetration testing tasks such as crawling, bruteforcing, and batch PoC/EXP ver… | 23 | 1936 | maintenance |
| inbug-team/InScan InScan is a Go-based automated intranet penetration testing tool designed for use after breaching a network boundary. It provides port scan… | 32 | 1888 | maintenance |
| google/security-research-pocs A collection of proof-of-concept exploit code produced during security research by the Google Security Team. It serves as a reference repos… | 10 | 1880 | maintenance |
| 0xInfection/TIDoS-Framework TIDoS is a Python-based offensive web application penetration testing framework with a Metasploit-like console interface and an optional Qt… | 23 | 1868 | maintenance |
| jaykali/hackerpro HackerPro is an all-in-one penetration testing tool collection for Linux and Android (Termux) that bundles popular security tools like Nmap… | 32 | 1852 | maintenance |
| awake1t/linglong Linglong is a self-hosted asset reconnaissance and scanning system written in Go that continuously discovers network assets using masscan+n… | 32 | 1846 | maintenance |
| pmiaowu/BurpShiroPassiveScan A passive BurpSuite extension written in Java that automatically detects Apache Shiro framework usage and tests for known Shiro encryption … | 23 | 1806 | maintenance |
| KimJun1010/WeblogicTool A GUI-based vulnerability exploitation toolkit targeting Oracle WebLogic servers, supporting detection and exploitation of numerous CVEs vi… | 20 | 1804 | maintenance |