SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Vulnerability Projects
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
if you've never worked on SQL injection that's fine there is a PWNSOME REPOSITORY(get it? pwn + awesome) called[ Payload All The Things (https://github.com/swisskyrepo/PayloadsAllTheThings) it has different payloads for different web vulnerabilities.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
-
malwoverview
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
-
cve-bin-tool
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
-
-
-
-
packj
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Project mention: Packj flags malicious/risky open-source packages | news.ycombinator.com | 2026-05-22 -
vulnerablecode
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
-
puncia
Panthera(P.)uncia - Official CLI utility for Osprey Vision, Subdomain Center & Exploit Observer.
-
-
Telegram-Trilateration
Proof of concept for abusing Telegram's "People Near Me" feature and tracking people's location
-
Egyscan
Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious threats. Let's delve into the tasks and functions that make Egyscan an indispensable tool in your security arsenal:
-
cyberowl
Aggregates security advisories from 10 international CERTs daily and provides an AI skill that cross-references alerts against your project's tech stack.
-
-
-
-
-
-
-
-
vunnel
Tool for collecting vulnerability data from various sources (used to build the grype database)
-
Python Vulnerability discussion
Python Vulnerability related posts
-
Anthropic's open-source framework for AI-powered vulnerability discovery
-
How to Check If Your Dependencies Are Vulnerable (30 Lines of Python)
-
We Let an AI Attack Our Security Pipeline. Here's What 412 Attacks Taught Us.
-
I ran npm audit and DepGra on the same project — here's what each one caught
-
39 CVEs in WebGoat. Only 36 Were Reachable.
-
GitHub's Ubuntu Runners Have 1,681 Packages and 9 High Vulns
-
Panic at the CVE-o-theque [video]
-
A note from our sponsor - SaaSHub
www.saashub.com | 13 Jun 2026
Index
What are some of the best open-source Vulnerability projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | PayloadsAllTheThings | 78,311 |
| 2 | faraday | 6,518 |
| 3 | malwoverview | 3,864 |
| 4 | cve-bin-tool | 1,701 |
| 5 | quark-engine | 1,684 |
| 6 | VulnWhisperer | 1,396 |
| 7 | vulnix | 787 |
| 8 | packj | 686 |
| 9 | vulnerablecode | 667 |
| 10 | puncia | 662 |
| 11 | SIET | 594 |
| 12 | Telegram-Trilateration | 590 |
| 13 | Egyscan | 299 |
| 14 | cyberowl | 258 |
| 15 | RVD | 221 |
| 16 | gvm-tools | 198 |
| 17 | SSVC | 182 |
| 18 | PoC-CVE-2022-30190 | 157 |
| 19 | kitsec-core | 149 |
| 20 | CVE-2024-9264 | 130 |
| 21 | ShellShockHunter | 123 |
| 22 | vunnel | 121 |
| 23 | nvdlib | 114 |