A monitoring hub that watches popular open-source repositories and uses AI to detect when commits are patching security vulnerabilities - often before a CVE is even assigned. Findings are published to a retro-themed website with an RSS feed.
☆161Sep 1, 2026Updated 3 weeks ago
Alternatives and similar repositories for vulnerability-spoiler-alert
Users that are interested in vulnerability-spoiler-alert are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- GitHub Action to alert on security patches before the CVE drops.☆222Sep 10, 2026Updated 2 weeks ago
- My code and notes for "From Day Zero to Zero Day", a book on vulnerability research by Eugene Lim.☆37Nov 10, 2025Updated 10 months ago
- Scripts that I've written that others may find useful☆14Aug 17, 2022Updated 4 years ago
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆77Sep 21, 2026Updated last week
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Dec 29, 2021Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated 2 months ago
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆35Nov 17, 2018Updated 7 years ago
- SAST + LLM Interprocedural Context Extractor☆209Oct 28, 2025Updated 10 months ago
- A Python tool for discovering, downloading, and extracting metadata from publicly available files on target domains. Useful for OSINT.☆16Nov 7, 2025Updated 10 months ago
- Scripts and examples for "From Day Zero to Zero Day" by Eugene Lim.☆275Jun 18, 2026Updated 3 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,828Updated this week
- Adobe Experience Manager (AEM) hacking toolkit☆118Sep 26, 2025Updated last year
- Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never resear…☆124Feb 22, 2026Updated 7 months ago
- GhostCVEs☆22Updated this week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Results from analyzing data gathered from 1.6 billion subdomains☆33Oct 15, 2024Updated last year
- jxscout superpowers JavaScript analysis for security researchers☆470Apr 12, 2026Updated 5 months ago
- Abuse trust-boundaries to bypass firewalls and network controls☆434Jul 10, 2026Updated 2 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆131Updated this week
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆28Dec 5, 2025Updated 9 months ago
- Filter and enrich a list of subdomains by level☆217Sep 25, 2023Updated 3 years ago
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆448Sep 21, 2026Updated last week
- PoC for leaking text nodes via CSS injection☆26Jul 27, 2024Updated 2 years ago
- The Java Burp Extension version of my BypassFuzzer tool☆40Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆16Jun 23, 2024Updated 2 years ago
- A Firefox Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆28Dec 9, 2024Updated last year
- web app monitoring automation☆15Jan 7, 2025Updated last year
- Malicious package & supply-chain intelligence☆198Sep 2, 2026Updated 3 weeks ago
- Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.☆946Aug 28, 2026Updated last month
- 🐛 A list of writeups from the MSRC (Microsoft) Bug Bounty program☆40Oct 29, 2025Updated 10 months ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆187Updated this week
- Manage attack surface data on Elasticsearch☆26Nov 20, 2023Updated 2 years ago
- Fuzzing All Native Android System Services with Interface Awareness and Coverage☆44Sep 8, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- List of custom Nuclei templates☆16Nov 4, 2023Updated 2 years ago
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆91Updated this week
- Useful scripts for tampermonkey that I used during bug hunting. Will be updated "au fil de l'eau"☆18Jun 2, 2025Updated last year
- Bruteforcing from various scanner output - Automatically attempts default creds on found services.☆15Mar 10, 2025Updated last year
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- Inline proxy for software package registries to provide observability and policy controls to installs.☆53Updated this week
- MCP server for Delve debugger integration☆20Dec 2, 2025Updated 9 months ago