Powerful document editing and collaboration in your app or environment. Ultimate security, API and 30+ ready connectors, SaaS or on-premises Learn more →
Top 23 Python Vulnerability Projects
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Project mention: Becoming a security researcher. Help with a realistic timeline? | reddit.com/r/AskNetsec | 2023-05-17- https://github.com/swisskyrepo/PayloadsAllTheThings - https://book.hacktricks.xyz/welcome/readme
-
or you can also use our open source version: https://github.com/infobyte/faraday
-
Sonar
Write Clean Python Code. Always.. Sonar helps you commit clean code every time. With over 225 unique rules to find Python bugs, code smells & vulnerabilities, Sonar finds the issues while you focus on the work.
-
-
Project mention: Pyscan: A command-line tool to detect security issues in your python dependencies. | reddit.com/r/Python | 2023-05-17
https://osv.dev its open source and even has a free API with almost all the popular languages. One of the inspirations for my project.
-
Im having a similar problem. Im running the cisco-siet.nse included in https://github.com/frostbits-security/SIET.git. Other nmap (non-script) commands seem to complete as well and simply say segmentation fault at the end. I can provide more information. I'm not sure what would be helpful, this is beyond my scope of knowledge.
-
packj
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
I built Packj [1] sandboxing for securing “pip/NPM install”. It uses strace for sandboxing and blocks access to sensitive files and limits traffic to known-good IP addresses.
-
Telegram-Trilateration
Proof of concept for abusing Telegram's "People Near Me" feature and tracking people's location
-
ONLYOFFICE
ONLYOFFICE Docs — document collaboration in your environment. Powerful document editing and collaboration in your app or environment. Ultimate security, API and 30+ ready connectors, SaaS or on-premises
-
vulnerablecode
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
$ git clone https://github.com/nexB/vulnerablecode.git $ cd vulnerablecode $ make envfile $ docker-compose build
-
it is very easy to scan your entire dependency tree for known vulnerabilities for Nix, all the way up to a whole OS
-
-
cyberowl
A daily updated summary of the most frequent types of security incidents currently being reported from different sources.
Project mention: Promote your business, week of May 15, 2023 | reddit.com/r/smallbusiness | 2023-05-15 -
Project mention: Zero-Click MS Office RCE Proof of Concept (MSDT Follina) | news.ycombinator.com | 2022-06-01
-
dheater
D(HE)ater is a proof of concept implementation of the D(HE)at attack (CVE-2002-20001) through which denial-of-service can be performed by enforcing the Diffie-Hellman key exchange.
-
Greenbone vulnerability scanner. Script to create scan targets from a file with list of hosts (link to script)
-
-
turing-machine
A Python program implementing and exploiting the Minsky Turing machine considered in the paper "Intrinsic Propensity for Vulnerability in Computers? Arbitrary Code Execution in the Universal Turing Machine" as per CVE-2021-32471 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32471)
-
-
bitcoin-recover-privkey
Proof of concept of bitcoin private key recovery using weak ECDSA signatures
Project mention: Are old wallet addresses reusable even if the address changes after a while? | reddit.com/r/BitcoinBeginners | 2022-07-16 -
-
dp_cryptomg
Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.
-
OrgASM
A tool for Oragnized ASM (Attack Surface Mapper). Subdomains enumeration, IPs scans, Vulnerability assesment...
Project mention: New Attack Surface Discovery tool : OrgASM | reddit.com/r/cybersecurity | 2023-05-31 -
wpsec
-
-
CodiumAI
TestGPT | Generating meaningful tests for busy devs. Get non-trivial tests (and trivial, too!) suggested right inside your IDE, so you can code smart, create more value, and stay confident when you push.
Python Vulnerability related posts
- Announcing Pyscan: A dependency vulnerability scanner for python projects.
- I launched my first SaaS on ProductHunt and I don't know if I should have
- A tool that aggregates security advisories from multiple sources. You can get them by email!
- I built a tool that aggregates security advisories from multiple sources. You can get them by email!
- Kaseya Acquired Vonahi Security
- Show HN: TypeScript Security Scanner
- Distributed vulnerability database for Open Source
-
A note from our sponsor - ONLYOFFICE
www.onlyoffice.com | 31 May 2023
Index
What are some of the best open-source Vulnerability projects in Python? This list will help you:
Project | Stars | |
---|---|---|
1 | PayloadsAllTheThings | 47,941 |
2 | faraday | 3,950 |
3 | VulnWhisperer | 1,300 |
4 | osv.dev | 1,126 |
5 | SIET | 527 |
6 | packj | 518 |
7 | Telegram-Trilateration | 485 |
8 | vulnerablecode | 338 |
9 | vulnix | 307 |
10 | phpvuln | 275 |
11 | cyberowl | 219 |
12 | PoC-CVE-2022-30190 | 147 |
13 | dheater | 145 |
14 | gvm-tools | 143 |
15 | ShellShockHunter | 91 |
16 | turing-machine | 74 |
17 | nsa-codebreaker-2020 | 71 |
18 | bitcoin-recover-privkey | 63 |
19 | nvdlib | 46 |
20 | dp_cryptomg | 38 |
21 | OrgASM | 8 |
22 | wpsec-cli | 8 |
23 | Heartbleed | 6 |