A monitoring hub that watches popular open-source repositories and uses AI to detect when commits are patching security vulnerabilities - often before a CVE is even assigned. Findings are published to a retro-themed website with an RSS feed.
☆159Sep 1, 2026Updated last week
Alternatives and similar repositories for vulnerability-spoiler-alert
Users that are interested in vulnerability-spoiler-alert are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- GitHub Action to alert on security patches before the CVE drops.☆217Aug 17, 2026Updated 3 weeks ago
- My code and notes for "From Day Zero to Zero Day", a book on vulnerability research by Eugene Lim.☆37Nov 10, 2025Updated 9 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated 2 months ago
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆75Updated this week
- Scripts that I've written that others may find useful☆14Aug 17, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- SAST + LLM Interprocedural Context Extractor☆208Oct 28, 2025Updated 10 months ago
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Dec 29, 2021Updated 4 years ago
- Scripts and examples for "From Day Zero to Zero Day" by Eugene Lim.☆272Jun 18, 2026Updated 2 months ago
- Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never resear…☆122Feb 22, 2026Updated 6 months ago
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆35Nov 17, 2018Updated 7 years ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,726Updated this week
- A Python tool for discovering, downloading, and extracting metadata from publicly available files on target domains. Useful for OSINT.☆16Nov 7, 2025Updated 10 months ago
- Adobe Experience Manager (AEM) hacking toolkit☆117Sep 26, 2025Updated 11 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆127Updated this week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- The Java Burp Extension version of my BypassFuzzer tool☆40Updated this week
- jxscout superpowers JavaScript analysis for security researchers☆473Apr 12, 2026Updated 4 months ago
- GhostCVEs☆22Updated this week
- Useful scripts for tampermonkey that I used during bug hunting. Will be updated "au fil de l'eau"☆18Jun 2, 2025Updated last year
- Abuse trust-boundaries to bypass firewalls and network controls☆434Jul 10, 2026Updated last month
- Results from analyzing data gathered from 1.6 billion subdomains☆33Oct 15, 2024Updated last year
- Orchestrate fleets of Claude Code & Claude Computer Use agents across containers, VMs, and physical devices. Live desktop streaming, inte…☆149Mar 11, 2026Updated 5 months ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆27Dec 5, 2025Updated 9 months ago
- Filter and enrich a list of subdomains by level☆216Sep 25, 2023Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆89Updated this week
- A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).☆40Jan 13, 2026Updated 7 months ago
- A fast vulnerability scanner for package dependencies☆16Jul 22, 2026Updated last month
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆447Updated this week
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆182Updated this week
- AI-Powered Web Attack Surface Enumeration☆54Updated this week
- PoC for leaking text nodes via CSS injection☆26Jul 27, 2024Updated 2 years ago
- Unify your OAST provider management and consolidate all interactions into a single, streamlined workflow.☆26May 23, 2026Updated 3 months ago
- ☆16Jun 23, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A Firefox Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆28Dec 9, 2024Updated last year
- BURP extension providing a set of values for the HTTP request "Host" header for the "BURP Intruder" in order to abuse virtual host resolu…☆61Oct 8, 2017Updated 8 years ago
- Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.☆936Aug 28, 2026Updated last week
- VEDAS-Driven Autonomous Generation of Suricata Rules for CVEs☆20Jan 13, 2026Updated 7 months ago
- Multithreaded Host Header Redirection Scanner☆14Nov 10, 2020Updated 5 years ago
- web app monitoring automation☆15Jan 7, 2025Updated last year
- 🐛 A list of writeups from the MSRC (Microsoft) Bug Bounty program☆36Oct 29, 2025Updated 10 months ago