Top 105 cve open source projects

Awesome Cve Poc
✍️ A curated list of CVE PoCs.
✭ 2,812
Cve Bin Tool
This tool scans for a number of common, vulnerable components (openssl, libpng, libxml2, expat and a few others) to let you know if your system includes common libraries with known vulnerabilities.
Peiqi Wiki Poc
Cve 2020 16898
CVE-2020-16898 (Bad Neighbor) Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule
Sbt Dependency Check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈
Cve Check Tool
Original Automated CVE Checking Tool
Js Vuln Db
A collection of JavaScript engine CVEs with PoCs
Vulnerability (CVE) scanner for Nix/NixOS.
Containing Self Made Perl Reproducers / PoC Codes
Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity
This repo records all the vulnerabilities of linux software I have reproduced in my local workspace
pigat ( Passive Intelligence Gathering Aggregation Tool ) 被动信息收集聚合工具
WPrecon (WordPress Recon), is a vulnerability recognition tool in CMS Wordpress, developed in Go and with scripts in Lua.
Nist Data Mirror
A simple Java command-line utility to mirror the CVE JSON data from NIST.
Awesome Csirt
Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.
OSINT tool - gets data from services like shodan, censys etc. in one app
Gitlab rce
RCE for old gitlab version <= 11.4.7 & 12.4.0-12.8.1 and LFI for old gitlab versions 10.4 - 12.8.1
Middleware Vulnerability Detection
CVE、CMS、中间件漏洞检测利用合集 Since 2019-9-15
✭ 1,378
cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vulnerabilities & PoCs
The clever vulnerability dependency finder
Cve 2018 20555
Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555
Ossf Cve Benchmark
The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebases using a variety of static analysis security testing (SAST) tools and generate reports to evaluate those tools.
Vulnerability Data Archive
With the hope that someone finds the data useful, we periodically publish an archive of almost all of the non-sensitive vulnerability information in our vulnerability reports database. See also
Security Checker Action
The PHP Security Checker
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞利用功能
Sudo killer
A tool to identify and exploit sudo rules' misconfigurations and vulnerabilities within sudo for linux privilege escalation.
IVA is a system to scan for known vulnerabilities in software products installed inside an organization. IVA uses CPE identifiers to search for CVEs related to a software product.
🌴Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file
✭ 972
Vulnerability Labs for security analysis
Cve 2020 15906
Writeup of CVE-2020-15906
Snyk Js Jquery 174006
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
✭ 21
Cve 2017 0065
Exploiting Edge's read:// urlhandler
Poc Collected for study and develop
Resources for Windows exploit development
ES File Explorer Open Port Vulnerability - CVE-2019-6447
Uxss Db
🔪Browser logic vulnerabilities ☠️
Java Deserialization Exploits
A collection of curated Java Deserialization Exploits
Cve 2018 8120
CVE-2018-8120 Windows LPE exploit
✭ 447
Hardware And Firmware Security Guidance
Guidance for the Spectre, Meltdown, Speculative Store Bypass, Rogue System Register Read, Lazy FP State Restore, Bounds Check Bypass Store, TLBleed, and L1TF/Foreshadow vulnerabilities as well as general hardware and firmware security guidance. #nsacyber
CVE Alerting Platform
WebMap-Nmap Web Dashboard and Reporting
快速搭建各种漏洞环境(Various vulnerability environment)
BootStomp: a bootloader vulnerability finder
Faraday introduces a new concept - IPE (Integrated Penetration-Test Environment) a multiuser Penetration test IDE. Designed for distributing, indexing, and analyzing the data generated during a security audit.
Penetration testing poc
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss penetration-testing-poc csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
Cve 2019 1003000 Jenkins Rce Poc
Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
Documentation and Sharing Repository for ThreatPinch Lookup Chrome & Firefox Extension
A PHP version scanner for reporting possible vulnerabilities
Master list of all my vulnerability discoveries. Mostly 3rd party kernel drivers.
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps. 👻🐚
1-60 of 105 cve projects