Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: vulnerability-scanning

447 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
iceyhexman/onlinetools
A self-hosted web-based penetration testing toolbox written in Python that bundles common recon and scanning tasks behind a browser UI. It …
101788maintenance
Moham3dRiahi/XAttacker
XAttacker is a Perl-based command-line tool that scans websites for vulnerabilities and automatically exploits them. It detects the target'…
321757maintenance
al0ne/Vxscan
Vxscan is a Python3-based comprehensive security scanning tool for authorized penetration testing. It combines host liveness checks, port s…
321755maintenance
DanMcInerney/xsscrapy
A Python-based spider built on Scrapy that crawls a website and tests every link it finds for cross-site scripting (XSS) and basic SQL inje…
321747maintenance
Cybereason/Logout4Shell
A Java-based proof-of-concept tool by Cybereason that exploits the Log4Shell vulnerability (CVE-2021-44228) to 'vaccinate' a vulnerable ser…
321692maintenance
Ghr07h/Heimdallr
Heimdallr is a fully passive Chrome extension for security professionals that identifies high-risk vulnerability framework fingerprints in …
231681maintenance
rasta-mouse/Watson
Watson is a .NET console tool that enumerates missing Windows KB patches and suggests exploits for known privilege escalation vulnerabiliti…
101680maintenance
opensec-cn/kunpeng
Kunpeng is an open-source vulnerability POC (proof-of-concept) detection framework written in Go, bundling POCs for databases, middleware, …
231663maintenance
veo/vscan
vscan is an open-source, lightweight, fast, cross-platform website vulnerability scanner written in Go, built for red team reconnaissance. …
231632maintenance
stark0de/nginxpwner
Nginxpwner is a Python command-line tool that scans Nginx servers for common misconfigurations and known vulnerabilities, such as CRLF inje…
101599maintenance
tokyoneon/Chimera
Chimera is a PowerShell obfuscation script that transforms malicious PS1 payloads using string substitution and variable concatenation to b…
321597maintenance
Lotus6/ThinkphpGUI
A Java-based GUI vulnerability exploitation tool targeting the ThinkPHP framework, supporting detection of vulnerabilities across ThinkPHP …
231595maintenance
wyzxxz/shiro_rce_tool
A Java-based command-line tool that assists in detecting and exploiting Apache Shiro rememberMe deserialization vulnerabilities. It brute-f…
321594maintenance
XiphosResearch/exploits
A collection of miscellaneous proof-of-concept exploit scripts written by Xiphos Research for security testing purposes, covering CVEs acro…
321575maintenance
v3n0m-Scanner/V3n0M-Scanner
V3n0M is an offensive security framework and vulnerability scanner written in Python 3.6+ using asyncio. It scans for SQLi, XSS, LFI/RFI vu…
231573maintenance
google/log4jscanner
A Go-based filesystem scanner and library that detects JAR files containing the vulnerable Log4j classes behind the Log4Shell vulnerability…
101562maintenance
s0md3v/Corsy
Corsy is a lightweight Python 3 CLI tool that scans websites for known CORS (Cross-Origin Resource Sharing) misconfigurations. It tests for…
231534maintenance
GhostPack/SharpUp
SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat…
321531maintenance
HummerRisk/HummerRisk
HummerRisk is an open-source, agentless cloud-native security platform for hybrid cloud security governance and Kubernetes/container securi…
231512maintenance
pentestmonkey/windows-privesc-check
A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv…
321500maintenance
lunasec-io/lunasec
LunaSec is an open-source supply chain security suite whose main product, LunaTrace, scans project dependencies for vulnerabilities like Lo…
231469maintenance
psecio/iniscan
A command-line tool that scans a php.ini file against common security best practices and reports pass/fail results per setting. It is insta…
321468maintenance
woodpecker-framework/woodpecker-framework-release
Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne…
231463maintenance
SamJoan/droopescan
Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti…
321445maintenance
jweny/pocassist
Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web …
101436maintenance
cube0x0/noPac
A C# tool that scans for and exploits the CVE-2021-42287/CVE-2021-42278 Active Directory vulnerability chain, allowing a standard domain us…
321412maintenance
Lucifer1993/struts-scan
A Python2 command-line tool that detects and exploits Apache Struts2 remote code execution vulnerabilities across all major versions (ST2-0…
321412maintenance
TideSec/Mars
Mars is a self-hosted security platform for asset discovery, subdomain enumeration, port and web fingerprinting, and change monitoring of i…
321376maintenance
jeffzh3ng/fuxi
Fuxi is a self-hosted penetration testing platform written in Python that provides a web interface for organizing and running security asse…
321346maintenance
LittleBear4/OA-EXPTOOL
A Python-based exploitation framework targeting Chinese OA (Office Automation) systems, bundling nearly 20 batch vulnerability scanners for…
231345maintenance
enzymefinance/oyente
Oyente is a static analysis tool for Ethereum smart contracts that detects security vulnerabilities using symbolic execution of EVM bytecod…
101338maintenance
4ra1n/super-xray
Super Xray is a Java-based GUI launcher for the xray web vulnerability scanner, wrapping its command-line interface and config.yaml setup i…
101325maintenance
stampery/mongoaudit
mongoaudit is a Python CLI tool that audits MongoDB servers for poor security configurations, known vulnerabilities, and misconfigurations.…
231324maintenance
stelligent/cfn_nag
cfn_nag is a command-line linting tool that scans AWS CloudFormation templates for insecure infrastructure patterns such as overly permissi…
231309maintenance
k8gege/K8CScan
K8CScan is a high-concurrency, plugin-based scanner designed for large internal network penetration testing. It bundles information gatheri…
321303maintenance
netxfly/x-crack
x-crack is a command-line weak password (credential brute-force) scanner written in Go that tests common username/password combinations aga…
231276maintenance
UzJu/Cloud-Bucket-Leak-Detection-Tools
A Python CLI tool that detects misconfigured and leaked cloud storage buckets across six major cloud providers including Aliyun, Tencent Cl…
291266maintenance
Cybellum/DoubleAgent
DoubleAgent is a research tool and proof-of-concept demonstrating a zero-day code injection and persistence technique on Windows, exploitin…
321262maintenance
pmiaowu/BurpFastJsonScan
A passive BurpSuite extension written in Java that detects FastJson deserialization vulnerabilities in JSON-bearing HTTP requests. It autom…
231251maintenance
W01fh4cker/Serein
Serein is a graphical Python tool for batch-collecting URLs via the FOFA search engine API and running batch detection/exploitation of know…
101250maintenance
eliasgranderubio/dagda
Dagda is a Python-based security tool that performs static analysis of known vulnerabilities, trojans, viruses, and malware in Docker image…
231248maintenance
blst-security/cherrybomb
Cherrybomb is a Rust-based CLI tool that audits OpenAPI specifications for best practices and OAS compliance, then runs security tests agai…
231234maintenance
AndroBugs/AndroBugs_Framework
AndroBugs Framework is a command-line Android vulnerability scanner that analyzes APK files to find potential security vulnerabilities and …
101224maintenance
hacktoolspack/hack-tools
A curated collection of free hacking and cybersecurity tools covering DoS, information gathering, malware/ransomware generation, and remote…
231218maintenance
elkokc/reflector
Reflector is a Burp Suite extension written in Java that detects reflected XSS vulnerabilities in real time while browsing a target web app…
231214maintenance
OWASP/joomscan
OWASP JoomScan is an open-source Perl-based vulnerability scanner for Joomla CMS deployments. It enumerates versions, components, and known…
231192maintenance
Ekultek/BlueKeep
A Python proof-of-concept exploit for CVE-2019-0708 (BlueKeep), a pre-authentication remote code execution vulnerability in Microsoft RDP a…
651183maintenance
timwhitez/crawlergo_x_XRAY
A Python glue script that combines the crawlergo dynamic crawler with the XRAY passive vulnerability scanner, replaying crawled URLs throug…
321182maintenance
dionach/CMSmap
CMSmap is a Python open-source CLI scanner that automates detection of security flaws in popular CMSs, integrating common vulnerabilities f…
321176maintenance
Lucifer1993/SatanSword
SatanSword is a Python-based red team penetration testing framework that integrates web fingerprinting, PoC-based vulnerability detection, …
321171maintenance
tongcheng-security-team/NextScan
NextScan (飞刃) is an enterprise-grade distributed black-box vulnerability scanning platform built in Go, composed of Server, Agent, and Web …
211164maintenance
chenjj/CORScanner
CORScanner is a fast Python tool for detecting CORS misconfiguration vulnerabilities in websites, using gevent for high-concurrency network…
231162maintenance
Lucifer1993/TPscan
TPscan is a one-click vulnerability detection tool for ThinkPHP applications, written in Python 3. It scans ThinkPHP-based web services for…
321159maintenance
techjacker/repo-security-scanner
A Go CLI tool that scans a git repository's history for accidentally committed secrets such as passwords and private keys. It processes the…
231158maintenance
d3ckx1/Fvuln
Fvuln (Find-Vulnerability) is an automated security scanning tool for penetration testers and red teams. It combines live IP detection, por…
231157maintenance
anshumanbh/git-all-secrets
git-all-secrets is a Go CLI tool that clones GitHub/GitHub Enterprise repositories, gists, and organization or team repos, then scans them …
321144maintenance
1n7erface/Template
Template is a heuristic intranet scanning CLI tool built for red team operations, combining host discovery, port scanning, web fingerprinti…
231121maintenance
JackOfMostTrades/gadgetinspector
A Java bytecode analyzer that automatically discovers deserialization gadget chains in Java libraries and application classpaths. It produc…
321090maintenance
pentestmonkey/unix-privesc-check
A single shell script that audits Unix systems for misconfigurations allowing local privilege escalation. It can be uploaded and run direct…
321082maintenance
ajinabraham/CMSScan
CMSScan is a self-hosted security dashboard that scans WordPress, Drupal, Joomla, and vBulletin websites for vulnerabilities by wrapping wp…
321078maintenance
a1phaboy/FastjsonScan
FastjsonScan is a Go-based command-line scanner that detects Fastjson deserialization vulnerabilities in Java web services. It identifies t…
231055maintenance
doyensec/electronegativity
Electronegativity is a CLI-based SAST tool that scans Electron applications for misconfigurations and security anti-patterns using AST and …
401054maintenance
momosecurity/momo-code-sec-inspector-java
An IntelliJ IDEA plugin by Momo Security that performs static security analysis of Java code in real time using IDEA's native Inspection me…
321048maintenance
WithSecureLabs/doublepulsar-detection-script
A Python 2 script that sweeps networks to detect Windows systems compromised with the DOUBLEPULSAR implant (SMB and RDP variants) released …
321030maintenance
admintony/svnExploit
SvnExploit is a Python CLI tool that exploits SVN source code disclosure vulnerabilities, supporting both SVN <1.7 and >1.7 repository form…
321029maintenance
b3-v3r/Hunner
Hunner is a Python-based hacking framework for penetration testing that combines vulnerability scanning (SQL injection, XSS), denial-of-sit…
321012maintenance
c0ny1/java-memshell-scanner
A JSP-based scanner that detects and helps remove Java web memory shells (memshells) such as Filter, Servlet, and Listener types in middlew…
321012maintenance
TheKingOfDuck/ApkAnalyser
A Python-based command-line tool that extracts potentially sensitive information from Android APK files, including URLs, IPs, hashes, acces…
231004maintenance
snyk/agent-scan
Snyk Agent Scan is a Python-based CLI security scanner that discovers installed AI agent components (agent harnesses, MCP servers, and agen…
822958experimental
s0md3v/Striker
Striker is a Python-based offensive reconnaissance and vulnerability scanning suite that discovers subdomains, scans common ports, detects …
232341experimental
MSNightmare/RoguePlanet
RoguePlanet is a proof-of-concept exploit for a Windows Defender vulnerability written in C++. It uses a race condition (triggered via ISO …
521618experimental
achuna33/MYExploit
MYExploit is a Java-based one-click scanning and exploitation tool targeting OA (office automation) enterprise products, built as an extens…
231485experimental
koutto/jok3r
Jok3r is a Python3 CLI framework that automates network and web black-box penetration testing by chaining 50+ open-source security tools. I…
321087experimental
tenable/terrascan
Terrascan is a static code analyzer for Infrastructure as Code that detects compliance and security violations across Terraform, CloudForma…
105211abandoned
aquasecurity/kube-hunter
kube-hunter is a Python-based tool that hunts for security weaknesses and vulnerabilities in Kubernetes clusters, running remotely, on a ma…
235078abandoned
zhzyker/exphub
Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, …
324291abandoned
Arachni/arachni
Arachni is a modular, high-performance Ruby framework for scanning web applications for security vulnerabilities, including XSS and SQL inj…
104039abandoned
eth0izzle/shhgit
shhgit is a secrets detection tool that scans GitHub, GitLab, Bitbucket repositories and local directories for accidentally committed crede…
363977abandoned
FeeiCN/Cobra
Cobra is a source code security audit (SAST) tool that scans PHP, Java, and other languages for common vulnerabilities like SQL injection, …
103186abandoned
jaeles-project/jaeles
Jaeles is a Go-based framework for building and running automated web application vulnerability scanners using customizable YAML signatures…
622370abandoned
praetorian-inc/noseyparker
Nosey Parker is a Rust-based command-line secrets scanner that finds credentials and sensitive information in files, directories, GitHub, a…
102341abandoned
python-security/pyt
PyT (Python Taint) is a static analysis tool that detects security vulnerabilities like injection flaws in Python web applications using ta…
232201abandoned
rasta-mouse/Sherlock
Sherlock is a PowerShell script that identifies missing software patches for known Windows local privilege escalation vulnerabilities. It i…
102020abandoned
feihong-cs/ShiroExploit-Deprecated
A Java-based one-click exploitation tool for Apache Shiro vulnerabilities Shiro550 (hardcoded key) and Shiro721 (Padding Oracle), supportin…
231956abandoned
Shopify/kubeaudit
kubeaudit is a command line tool and Go package that audits Kubernetes clusters against common security controls like running as non-root, …
101936abandoned
mozilla/http-observatory
Mozilla HTTP Observatory is a Python-based scanner and grader that analyzes websites' HTTP headers and security configurations, providing a…
101850abandoned
nodesecurity/nsp
nsp is the Node Security Platform command-line tool that checks Node.js projects for known vulnerabilities in their dependencies, with CVSS…
101653abandoned
anchore/anchore-engine
Anchore Engine is an open-source service that inspects, analyzes, and certifies container images, scanning them against a vulnerability dat…
101589abandoned
Lucifer1993/AngelSword
AngelSword is a simple CMS vulnerability detection framework written in Python3, designed to help security engineers quickly discover known…
321441abandoned
aquasecurity/starboard
Starboard is a Kubernetes-native security toolkit that integrates heterogeneous security scanners and exposes their results as Kubernetes C…
851380abandoned
hahwul/XSpear
XSpear is a Ruby-based XSS (cross-site scripting) scanner and parameter analysis tool distributed as a gem, usable both as a CLI and as a R…
101364abandoned
cisagov/log4j-scanner
A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE…
101278abandoned
forseti-security/forseti-security
Forseti Security is a collection of open-source tools for auditing and improving the security of Google Cloud Platform environments, includ…
101269abandoned
the-robot/sqliv
SQLiv is a Python command-line tool that scans websites for SQL injection vulnerabilities. It supports dork-based scanning via search engin…
101229abandoned
mozilla/mig
MIG (Mozilla InvestiGator) is a distributed platform for real-time digital forensics and endpoint investigation, using agents installed acr…
101202abandoned
fabpot/local-php-security-checker
A command-line tool that checks PHP applications using Composer for dependencies with known security vulnerabilities, backed by the Friends…
101182abandoned
SecurityFTW/cs-suite
Cloud Security Suite (cs-suite) is a command-line audit tool that checks the security posture of AWS, GCP, Azure, and DigitalOcean accounts…
321171abandoned
fit2cloud/riskscanner
RiskScanner is an open-source multi-cloud security compliance scanning platform built on Cloud Custodian, Prowler, and Nuclei engines. It p…
101152abandoned
ring04h/weakfilescan
A Python-based multi-threaded sensitive information leakage detection tool that crawls a target site, dynamically builds dictionary rules f…
321138abandoned
1n7erface/PocList
A Java-based collection of proof-of-concept (PoC) tools for verifying and exploiting known vulnerabilities in products like Nacos, WebLogic…
321075abandoned

← prev page 4 / 5 next →