resource: vulnerability-scanning
164 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| swisskyrepo/PayloadsAllTheThings A curated collection of payloads, bypasses, and exploitation techniques for web application security testing. It serves as a reference chea… | 66 | 80407 | active |
| The-Art-of-Hacking/h4cker A large curated collection of cybersecurity resources covering ethical hacking, penetration testing, DFIR, AI security, exploit development… | 76 | 29141 | active |
| enaqx/awesome-pentest A curated awesome-list of penetration testing and offensive security resources, tools, books, conferences, and training materials. It organ… | 75 | 27017 | active |
| sbilly/awesome-security A curated, community-driven awesome list of security software, libraries, books, documents, and resources. It organizes tools across catego… | 60 | 14797 | active |
| projectdiscovery/nuclei-templates A community-curated collection of YAML-based templates for the Nuclei vulnerability scanner, used to detect security vulnerabilities, misco… | 99 | 12849 | active |
| knownsec/404StarLink 404StarLink is a curated showcase program by Knownsec 404 Lab that collects, tracks, and promotes high-quality open-source security project… | 75 | 11131 | active |
| ashishb/android-security-awesome A curated awesome-list of Android security-related resources, including tools, academic publications, and exploit/vulnerability references.… | 76 | 9646 | active |
| toniblyx/my-arsenal-of-aws-security-tools A curated list of open-source security tools for AWS, organized into defensive, offensive, purple teaming, continuous auditing, DFIR, and d… | 73 | 9502 | active |
| We5ter/Scanners-Box A curated awesome-list of 9,000+ open-source cybersecurity tools covering subdomain enumeration, SQL injection, red team/blue team tooling,… | 76 | 9024 | active |
| LOLBAS-Project/LOLBAS A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques… | 77 | 8771 | active |
| trickest/cve An automatically updated repository collecting publicly available proof-of-concept exploits for CVEs, organized by year into markdown files… | 77 | 8026 | active |
| nomi-sec/PoC-in-GitHub An automatically curated dataset and web service that collects proof-of-concept (PoC) exploit repositories from GitHub as CVEs are publishe… | 77 | 8012 | active |
| guchangan1/All-Defense-Tool A curated, weekly auto-updated collection of open-source offensive and defensive security tools, covering information gathering, vulnerabil… | 77 | 7949 | active |
| 0xInfection/Awesome-WAF A curated awesome-list collecting everything about Web Application Firewalls (WAFs) from a security perspective, including how they work, d… | 77 | 7592 | active |
| Mr-xn/Penetration_Testing_POC A curated collection of penetration testing resources including POCs, exploits, scripts, privilege escalation tools, and write-ups for web … | 77 | 7471 | active |
| infoslack/awesome-web-hacking A curated awesome-list of resources for learning web application security, including books, documentation, tools, cheat sheets, courses, la… | 76 | 7246 | active |
| vavkamil/awesome-bugbounty-tools A curated awesome-list of bug bounty and web security tools, organized by recon and exploitation categories. It catalogs tools for subdomai… | 76 | 6199 | active |
| EdOverflow/can-i-take-over-xyz A community-maintained reference list of services vulnerable to subdomain takeover via dangling DNS records, with guidance on how to claim … | 34 | 5788 | active |
| fabacab/awesome-cybersecurity-blueteam A curated awesome-list of free and open-source resources, tools, and references for cybersecurity blue teams focused on defensive security.… | 32 | 5541 | active |
| Awesome-POC A curated knowledge base of 1k+ vulnerability Proof-of-Concept (PoC) writeups covering CVEs across CMSs, servers, and network devices. It i… | 68 | 5171 | active |
| s0md3v/AwesomeXSS A curated awesome-list of cross-site scripting (XSS) resources including payloads, polyglots, cheatsheets, tools, challenges, and papers. I… | 32 | 5138 | active |
| google/security-research A repository of security advisories and proof-of-concept exploits from Google security research affecting third-party (non-Google) software… | 77 | 4615 | active |
| A-poc/BlueTeam-Tools A curated collection of 70+ tools and resources for blue teaming and incident response, organized as a wiki-style cheatsheet. It covers thr… | 76 | 4456 | active |
| Az0x7/vulnerability-Checklist A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 40… | 30 | 3634 | active |
| snoopysecurity/awesome-burp-extensions A curated list of awesome Burp Suite extensions for web application security testing, organized by category such as scanners, fuzzers, and … | 76 | 3439 | active |
| Bo0oM/fuzz.txt A curated wordlist of potentially dangerous and sensitive file paths for web fuzzing and directory brute-forcing. It is commonly used with … | 75 | 3321 | active |
| coreruleset/coreruleset OWASP Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity, Coraza, or other compatible web application … | 99 | 3242 | stable |
| neargle/re0-kubernetes-sec-archive A curated archive of Kubernetes and container security attack/defense materials, including conference slides (BlackHat, HITB, KubeCon), pap… | 55 | 3164 | active |
| blackorbird/APT_REPORT A curated collection of APT (Advanced Persistent Threat) reports, malware samples, and special IOCs gathered from security vendors and rese… | 77 | 3084 | active |
| hacksysteam/HackSysExtremeVulnerableDriver HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable kernel driver for Windows and Linux designed for security researche… | 26 | 3083 | active |
| lirantal/awesome-nodejs-security A curated awesome-list of Node.js security resources, including tools for framework hardening, static and dynamic analysis, vulnerability a… | 76 | 3027 | active |
| CVE List An official mirror/cache of the CVE List maintained by the CVE Program, published as CVE Records in JSON 5 format. It is updated continuous… | 95 | 2934 | active |
| Endermanch/MalwareDatabase A curated GitHub collection of malware samples (rogue/PUP, trojans, ransomware, joke programs) archived with passwords for safe storage. It… | 74 | 2903 | active |
| threedr3am/learnjavabug A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jac… | 32 | 2687 | active |
| JoyChou93/java-sec-code A Spring Boot-based Java web application containing intentionally vulnerable code examples for common vulnerability types like SQLi, SSRF, … | 23 | 2673 | active |
| Mr-xn/RedTeam_BlueTeam_HW A curated collection of red team and blue team tools, documents, and reference materials for Chinese HW (HVV) attack-defense exercises. It … | 76 | 2643 | active |
| Lifka/hacking-resources A curated collection of hacking resources, cheat sheets, tools, scripts, and tutorials for offensive and defensive security professionals. … | 32 | 2611 | active |
| coffeehb/Some-PoC-oR-ExP A curated collection of proof-of-concept (PoC) scripts and exploits for various software vulnerabilities, written and gathered in Python. I… | 45 | 2502 | active |
| github/advisory-database A free, open-source database of security vulnerabilities, including CVEs and GitHub-originated security advisories, stored as individual fi… | 77 | 2441 | active |
| jgamblin/Mirai-Source-Code A mirror of the leaked Mirai botnet source code (bot, CnC server, loader) published for cybersecurity research, malware analysis, and indic… | 53 | 9457 | maintenance |
| terjanq/Tiny-XSS-Payloads A curated collection of minimal cross-site scripting (XSS) payloads organized by injection context, with an interactive demo site. It serve… | 32 | 2386 | active |
| fuzzdb-project/fuzzdb FuzzDB is a comprehensive open-source dictionary of attack payloads, predictable resource locations, and regex patterns for black-box appli… | 32 | 8980 | maintenance |
| immunefi-team/Web3-Security-Library A curated, collaborative library of resources for learning web3 and blockchain security, maintained by Immunefi. It aggregates guides, bloc… | 38 | 2193 | active |
| eeeeeeeeee-code/POC A curated backup of the wy876 vulnerability database collecting proof-of-concept exploits (POC/EXP) for a wide range of software, mostly Ch… | 61 | 2180 | active |
| FriendsOfPHP/security-advisories A community-maintained database of known security vulnerabilities in PHP Composer packages, stored as YAML files keyed by CVE or date. It c… | 77 | 2139 | active |
| m14r41/PentestingEverything A structured penetration testing knowledge base covering 23 security domains (web, mobile, API, cloud, network, Active Directory, SAST, Dev… | 83 | 2044 | active |
| hslatman/awesome-industrial-control-system-security A curated awesome-list of resources, tools, and references for Industrial Control System (ICS) and SCADA security. It catalogs tools for IC… | 53 | 2004 | active |
| eset/malware-ioc A repository of Indicators of Compromise (IOCs) published by ESET researchers from their malware investigations. It includes YARA rules and… | 72 | 1979 | active |
| yogsec/Hacking-Tools A curated list of penetration testing and ethical hacking tools organized by category, drawing from Kali Linux and other notable sources. I… | 65 | 1892 | active |
| safe6Sec/Fastjson A curated collection of Fastjson exploitation techniques, payloads, and fingerprinting tricks for Java JSON deserialization vulnerabilities… | 32 | 1860 | active |
| lutfumertceylan/top25-parameter OWASP Top 25 Parameters is a curated reference dataset of the 25 most commonly vulnerable parameter names for six vulnerability classes (XS… | 23 | 1847 | stable |
| ZhangZhuoSJTU/Web3Bugs A curated dataset of exploitable bugs in Solidity smart contracts, extracted from code4rena audit contests and classified by bug nature (ou… | 43 | 1819 | active |
| arch3rPro/PentestTools A curated awesome-list cataloging open-source penetration testing tools, organized by category and modeled on the Kali Tools listing. It se… | 67 | 1763 | active |
| magicsword-io/LOLDrivers LOLDrivers is a community-maintained curated dataset of vulnerable and malicious Windows drivers abused by adversaries (BYOVD attacks), wit… | 65 | 1763 | active |
| protectai/ai-exploits A collection of real-world AI/ML exploits and scanning templates for responsibly disclosed vulnerabilities in machine learning tools and in… | 27 | 1746 | active |
| B3nac/Android-Reports-and-Resources A curated list of disclosed HackerOne bug bounty reports and security resources focused on Android application vulnerabilities. It organize… | 51 | 1706 | active |
| LandGrey/SpringBootVulExploit A curated collection of Spring Boot vulnerability learning materials, exploitation methods, and a black-box security assessment checklist. … | 32 | 6144 | maintenance |
| github/securitylab The main repository of GitHub Security Lab, containing security research documentation, CodeQL query examples, and proof-of-concept exploit… | 62 | 1626 | active |
| phishdestroy/destroylist A continuously updated phishing and scam domain blocklist with 208k+ curated threats, distributed in multiple formats (hosts, AdBlock, Dnsm… | 72 | 1624 | active |
| psiinon/open-source-web-scanners A curated list of open source web security scanners hosted on GitHub and GitLab, ordered by stars. It serves as a discovery resource coveri… | 41 | 1615 | active |
| mazen160/secrets-patterns-db Secrets Patterns DB is the largest open-source database of over 1600 tested regular expressions for detecting secrets, API keys, passwords,… | 47 | 1609 | active |
| rapid7/metasploitable3 Metasploitable3 is a deliberately vulnerable virtual machine (Windows and Ubuntu builds) created by Rapid7 for practicing exploit developme… | 35 | 5681 | maintenance |
| SecWiki/linux-kernel-exploits A curated collection of Linux kernel privilege escalation exploits organized by CVE, with descriptions and affected kernel versions. It ser… | 32 | 5650 | maintenance |
| davinci1010/pinduoduo_backdoor A security research repository documenting analysis of privilege-escalation code embedded in the Pinduoduo Android APK, including a VMP-pac… | 30 | 5448 | maintenance |
| elastic/protections-artifacts Elastic's open repository of endpoint detection content, including EQL-based behavior rules, YARA malware rules, and ransomware protection … | 76 | 1482 | active |
| vavkamil/awesome-vulnerable-apps A curated awesome-list of intentionally vulnerable applications, VMs, and CTF platforms for practicing security skills. It covers web explo… | 71 | 1471 | active |
| Cyber-Guy1/API-SecurityEmpire A curated collection of mindmaps, tips, and resources for API security and API penetration testing, based on the OWASP API Top 10. It cover… | 32 | 1445 | active |
| BushidoUK/Ransomware-Tool-Matrix A curated knowledge base mapping the tools used by ransomware and extortion gangs, organized by category (RMM, exfiltration, credential the… | 65 | 1434 | active |
| bollwarm/SecToolSet A curated collection of GitHub security-related tools and projects, organized into categories like scanners, penetration testing, CTF pract… | 67 | 1423 | active |
| microsoft/MSRC-Security-Research A repository hosting security research published by the Microsoft Security Response Center (MSRC). It contains research papers, tools, and … | 32 | 1392 | active |
| 0xMarcio/cve A continuously updated hub aggregating the latest CVEs alongside links to their public Proof-of-Concept exploit repositories, with a web in… | 69 | 1365 | active |
| Yara-Rules/rules A community-maintained repository of YARA rules for malware and threat detection, organized into categories like anti-debug/anti-VM, CVEs, … | 32 | 4879 | maintenance |
| pashov/audits A public repository collecting smart contract security audit reports published by the Pashov Audit Group, organized by protocol category (l… | 76 | 1314 | active |
| topscoder/nuclei-wordfence-cve A collection of 80,000+ Nuclei vulnerability-scanning templates for WordPress core, plugins, and themes, generated daily from Wordfence thr… | 78 | 1278 | active |
| ax1sX/SecurityList A curated collection of web security and code audit resources, focused on Chinese enterprise software (OA systems), common Java components,… | 32 | 1262 | active |
| ybdt/exp-hub A curated collection of proof-of-concept (PoC) and exploit (Exp) scripts for reproducing known vulnerabilities, written primarily in HTML/J… | 76 | 1253 | active |
| CHYbeta/Web-Security-Learning A curated collection of links and learning materials on web security, covering SQL injection, XSS, CSRF, SSRF, XXE, file upload vulnerabili… | 32 | 4299 | maintenance |
| emadshanab/Nuclei-Templates-Collection A curated collection of links to community Nuclei template repositories, aggregating vulnerability detection templates for the Nuclei scann… | 58 | 1225 | active |
| ashishb/android-malware A curated collection of over 300 live Android malware samples gathered from multiple sources and mailing lists. It serves as a research dat… | 59 | 1222 | active |
| birdhan/SecurityProduct A curated awesome-list collecting open-source security products and projects, including IDS, IPS, WAF, honeypots, threat intelligence, vuln… | 62 | 1190 | active |
| yeswehack/vulnerable-code-snippets A collection of intentionally vulnerable code snippets (mostly PHP) published weekly by YesWeHack for practicing secure code analysis. Each… | 62 | 1176 | active |
| subat0mik/Misconfiguration-Manager A central knowledge base documenting known Microsoft Configuration Manager (SCCM/ConfigMgr) attack tradecraft along with defensive and hard… | 71 | 1167 | active |
| indianajson/can-i-take-over-dns A curated reference list of DNS providers and whether domains pointing to their nameservers are vulnerable to DNS (zone) takeover, with fin… | 76 | 1103 | active |
| Medicean/VulApps VulApps is a collection of Dockerized vulnerability environments (CVE-based, e.g. Struts2, Spring, Tomcat, Drupal) plus security tool envir… | 10 | 3783 | maintenance |
| SourByte05/Vulnerability-Wiki-PoC A continuously updated archive of 1-day/N-day vulnerability PoCs and reproduction write-ups focused on high-value enterprise assets such as… | 61 | 1099 | active |
| scadastrangelove/awesome-ai-security-tools A curated awesome-list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. It catalogs tools ac… | 59 | 1095 | active |
| nixawk/pentest-wiki A free online knowledge library (wiki) of penetration testing and security resources, organized into sections like information gathering, v… | 32 | 3751 | maintenance |
| rubysec/ruby-advisory-db A community-maintained database of security vulnerability advisories for Ruby gems and Ruby implementations, stored as YAML files identifie… | 77 | 1070 | active |
| R00tS3c/DDOS-RootSec A curated archive of DDoS-related source code and tools, including Mirai and QBot botnet variants, scanners, exploits, Layer 4/7 attack met… | 32 | 1053 | active |
| qazbnm456/awesome-cve-poc A curated awesome-list collecting proof-of-concept exploits for known CVEs, organized by CVE identifier. It serves as a reference index lin… | 32 | 3527 | maintenance |
| Ascotbe/Kernelhub A curated collection of kernel privilege escalation vulnerabilities for Windows, Linux, and macOS, including exploit code, compilation envi… | 23 | 3196 | maintenance |
| HackJava/HackJava A curated Chinese-language collection of Java security learning resources covering vulnerability analysis, code auditing, security tools, a… | 32 | 2893 | maintenance |
| ExpLangcn/NucleiTP A continuously updated aggregation of Nuclei vulnerability POC templates collected from across the web, organized by risk level. It automat… | 32 | 2877 | maintenance |
| Voorivex/pentest-guide A curated penetration testing guide that reorganizes the OWASP Testing Guide v4 into 9 test classes with concrete test cases, plus 15 extra… | 32 | 2826 | maintenance |
| wtsxDev/Penetration-Testing A curated awesome-list of penetration testing resources, including tools, distributions, books, courses, vulnerability databases, and secur… | 32 | 2783 | maintenance |
| mandiant/red_team_tool_countermeasures A repository of detection rules (Snort, YARA, ClamAV, HXIOC) released by Mandiant/FireEye for countering red team tools and threats. Rules … | 10 | 2665 | maintenance |
| r0eXpeR/redteam_vul A curated Chinese-language reference list of high-value vulnerabilities commonly encountered during red team operations, covering systems l… | 32 | 2524 | maintenance |
| nebgnahz/awesome-iot-hacks A curated awesome-list of documented IoT hacks, security vulnerabilities, research reports, and communities. It serves as a reference catal… | 32 | 2425 | maintenance |
| Bypass007/Safety-Project-Collection A curated Chinese-language list of excellent open-source security projects aimed at helping enterprise (blue-team/defender) security practi… | 32 | 2387 | maintenance |
| helloexp/0day A continuously updated collection of exploits (EXP) and proofs-of-concept (POC) for vulnerabilities in various CMS platforms, systems, and … | 32 | 2364 | maintenance |
page 1 / 2 next →