A monitoring hub that watches popular open-source repositories and uses AI to detect when commits are patching security vulnerabilities - often before a CVE is even assigned. Findings are published to a retro-themed website with an RSS feed.
☆155Aug 14, 2026Updated this week
Alternatives and similar repositories for vulnerability-spoiler-alert
Users that are interested in vulnerability-spoiler-alert are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- GitHub Action to alert on security patches before the CVE drops.☆217Aug 5, 2026Updated last week
- My code and notes for "From Day Zero to Zero Day", a book on vulnerability research by Eugene Lim.☆33Nov 10, 2025Updated 9 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆74Updated this week
- Scripts that I've written that others may find useful☆14Aug 17, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- SAST + LLM Interprocedural Context Extractor☆207Oct 28, 2025Updated 9 months ago
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Dec 29, 2021Updated 4 years ago
- Scripts and examples for "From Day Zero to Zero Day" by Eugene Lim.☆265Jun 18, 2026Updated 2 months ago
- Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never resear…☆121Feb 22, 2026Updated 5 months ago
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆35Nov 17, 2018Updated 7 years ago
- A Python tool for discovering, downloading, and extracting metadata from publicly available files on target domains. Useful for OSINT.☆17Nov 7, 2025Updated 9 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,636Updated this week
- Adobe Experience Manager (AEM) hacking toolkit☆116Sep 26, 2025Updated 10 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆123Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- jxscout superpowers JavaScript analysis for security researchers☆473Apr 12, 2026Updated 4 months ago
- The Java Burp Extension version of my BypassFuzzer tool☆37Updated this week
- Useful scripts for tampermonkey that I used during bug hunting. Will be updated "au fil de l'eau"☆18Jun 2, 2025Updated last year
- GhostCVEs☆22Updated this week
- Abuse trust-boundaries to bypass firewalls and network controls☆431Jul 10, 2026Updated last month
- Results from analyzing data gathered from 1.6 billion subdomains☆33Oct 15, 2024Updated last year
- Orchestrate fleets of Claude Code & Claude Computer Use agents across containers, VMs, and physical devices. Live desktop streaming, inte…☆145Mar 11, 2026Updated 5 months ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆27Dec 5, 2025Updated 8 months ago
- Filter and enrich a list of subdomains by level☆215Sep 25, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆86Updated this week
- A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).☆39Jan 13, 2026Updated 7 months ago
- A fast vulnerability scanner for package dependencies☆15Jul 22, 2026Updated 3 weeks ago
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆446Updated this week
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆176Updated this week
- AI-Powered Web Attack Surface Enumeration☆46Feb 5, 2026Updated 6 months ago
- PoC for leaking text nodes via CSS injection☆26Jul 27, 2024Updated 2 years ago
- Unify your OAST provider management and consolidate all interactions into a single, streamlined workflow.☆26May 23, 2026Updated 2 months ago
- ☆16Jun 23, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Firefox Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆28Dec 9, 2024Updated last year
- BURP extension providing a set of values for the HTTP request "Host" header for the "BURP Intruder" in order to abuse virtual host resolu…☆61Oct 8, 2017Updated 8 years ago
- Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.☆911Jul 1, 2026Updated last month
- Multithreaded Host Header Redirection Scanner☆14Nov 10, 2020Updated 5 years ago
- VEDAS-Driven Autonomous Generation of Suricata Rules for CVEs☆20Jan 13, 2026Updated 7 months ago
- Malicious package & supply-chain intelligence☆186Aug 9, 2026Updated last week
- web app monitoring automation☆15Jan 7, 2025Updated last year