A monitoring hub that watches popular open-source repositories and uses AI to detect when commits are patching security vulnerabilities - often before a CVE is even assigned. Findings are published to a retro-themed website with an RSS feed.
☆145Jul 28, 2026Updated this week
Alternatives and similar repositories for vulnerability-spoiler-alert
Users that are interested in vulnerability-spoiler-alert are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- GitHub Action to alert on security patches before the CVE drops.☆215Jul 5, 2026Updated 3 weeks ago
- My code and notes for "From Day Zero to Zero Day", a book on vulnerability research by Eugene Lim.☆33Nov 10, 2025Updated 8 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated 3 weeks ago
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆70Updated this week
- Scripts that I've written that others may find useful☆14Aug 17, 2022Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SAST + LLM Interprocedural Context Extractor☆206Oct 28, 2025Updated 9 months ago
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Dec 29, 2021Updated 4 years ago
- Scripts and examples for "From Day Zero to Zero Day" by Eugene Lim.☆261Jun 18, 2026Updated last month
- Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never resear…☆121Feb 22, 2026Updated 5 months ago
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆35Nov 17, 2018Updated 7 years ago
- A Python tool for discovering, downloading, and extracting metadata from publicly available files on target domains. Useful for OSINT.☆17Nov 7, 2025Updated 8 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,415Updated this week
- Adobe Experience Manager (AEM) hacking toolkit☆115Sep 26, 2025Updated 10 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆113Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- jxscout superpowers JavaScript analysis for security researchers☆473Apr 12, 2026Updated 3 months ago
- The Java Burp Extension version of my BypassFuzzer tool☆36Updated this week
- Useful scripts for tampermonkey that I used during bug hunting. Will be updated "au fil de l'eau"☆18Jun 2, 2025Updated last year
- GhostCVEs☆21Updated this week
- Abuse trust-boundaries to bypass firewalls and network controls☆424Jul 10, 2026Updated 2 weeks ago
- Results from analyzing data gathered from 1.6 billion subdomains☆33Oct 15, 2024Updated last year
- Orchestrate fleets of Claude Code & Claude Computer Use agents across containers, VMs, and physical devices. Live desktop streaming, inte…☆142Mar 11, 2026Updated 4 months ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆26Dec 5, 2025Updated 7 months ago
- Filter and enrich a list of subdomains by level☆215Sep 25, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆87Updated this week
- A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).☆37Jan 13, 2026Updated 6 months ago
- A fast vulnerability scanner for package dependencies☆15Jul 22, 2026Updated last week
- Notes I make for anything related to security.☆13Nov 3, 2022Updated 3 years ago
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆447Updated this week
- AI-Powered Web Attack Surface Enumeration☆46Feb 5, 2026Updated 5 months ago
- PoC for leaking text nodes via CSS injection☆26Jul 27, 2024Updated 2 years ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆168Updated this week
- Unify your OAST provider management and consolidate all interactions into a single, streamlined workflow.☆25May 23, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆16Jun 23, 2024Updated 2 years ago
- BURP extension providing a set of values for the HTTP request "Host" header for the "BURP Intruder" in order to abuse virtual host resolu…☆61Oct 8, 2017Updated 8 years ago
- Multithreaded Host Header Redirection Scanner☆14Nov 10, 2020Updated 5 years ago
- VEDAS-Driven Autonomous Generation of Suricata Rules for CVEs☆20Jan 13, 2026Updated 6 months ago
- Malicious package & supply-chain intelligence☆168Updated this week
- web app monitoring automation☆15Jan 7, 2025Updated last year
- 🐛 A list of writeups from the MSRC (Microsoft) Bug Bounty program☆36Oct 29, 2025Updated 9 months ago