awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 dépôts

Awesome GitHub RepositoriesVulnerability Data Synchronization

Mechanisms for updating local security definitions from remote vulnerability sources.

Distinct from Vulnerability Scanning: Focuses on the synchronization of vulnerability data rather than the act of scanning images or code.

Explore 14 awesome GitHub repositories matching security & cryptography · Vulnerability Data Synchronization. Refine with filters or upvote what's useful.

Awesome Vulnerability Data Synchronization GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • wpscanteam/wpscanAvatar de wpscanteam

    wpscanteam/wpscan

    9,636Voir sur GitHub↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Retrieves real-time security information from a remote database via API tokens to ensure scan accuracy.

    Ruby
    Voir sur GitHub↗9,636
  • trickest/cveAvatar de trickest

    trickest/cve

    7,882Voir sur GitHub↗

    This project is a vulnerability intelligence database and aggregator that organizes common vulnerabilities and exposures alongside their corresponding proof-of-concept exploit code. It functions as a security vulnerability tracker and an indexed directory of public exploit payloads. The system monitors new security flaws and updates to known exploits through repository watches and atom feeds. It utilizes automated aggregation to collect vulnerability details from centralized repositories and discovers associated exploit code via reference analysis and global searches. The tool provides capab

    Collects security flaw details and exploit references into a centralized, searchable format for researchers.

    HTMLcvecve-pocexploit
    Voir sur GitHub↗7,882
  • offensive-security/exploit-databaseAvatar de offensive-security

    offensive-security/exploit-database

    7,849Voir sur GitHub↗

    This project is a public exploit code archive and vulnerability database. It serves as a collection of documented software exploits and vulnerability data, providing a reference library of exploit scripts and payloads used to validate security flaws in target environments. The archive supports security threat intelligence, vulnerability research, and penetration testing workflows. It functions as a historical record of software vulnerabilities and the proof-of-concept code used to trigger them. The codebase is organized through directory-based categorization and flat-file data storage, utili

    Provides a centralized aggregator of vulnerability details and their corresponding proof-of-concept exploit code.

    Voir sur GitHub↗7,849
  • projectdiscovery/naabuAvatar de projectdiscovery

    projectdiscovery/naabu

    5,766Voir sur GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Filters CVE results by exploit status including known exploited, public PoCs, and remote exploitability.

    Gocdn-exclusionhacktoberfestnmap
    Voir sur GitHub↗5,766
  • bitsadmin/wesngAvatar de bitsadmin

    bitsadmin/wesng

    4,881Voir sur GitHub↗

    Ce projet est un ensemble d'utilitaires spécialisés pour l'évaluation des vulnérabilités Windows et l'audit de gestion des correctifs. Il fonctionne comme un scanner de vulnérabilités et un suggéreur d'exploits qui analyse les mises à jour installées pour identifier les correctifs de sécurité manquants et leurs vulnérabilités connues correspondantes. Le système se distingue en faisant correspondre les mises à jour manquantes avec une base de données de vulnérabilités consolidée pour recommander des exploits publiquement disponibles spécifiques. Il maintient la précision en synchronisant les bulletins de sécurité distants dans une base de données locale et en recoupant les lacunes identifiées avec les catalogues de mises à jour officiels pour gérer la supersédence des correctifs et éliminer les faux positifs. L'outil fournit des capacités pour l'analyse de la surface de sécurité, permettant aux utilisateurs de prioriser les lacunes à haut risque via un filtrage basé sur la sévérité et un affinement par date d'installation. Il inclut également un client de base de données pour la collecte et la synchronisation des mises à jour de définitions de sécurité provenant de multiples sources distantes.

    Updates local security definitions and exploit records from remote vulnerability sources.

    Pythonexploitmicrosoftpatches
    Voir sur GitHub↗4,881
  • greenbone/openvas-scannerAvatar de greenbone

    greenbone/openvas-scanner

    4,670Voir sur GitHub↗

    L'openvas-scanner est un scanner de vulnérabilités conçu pour identifier les faiblesses de sécurité et les logiciels obsolètes dans les systèmes cibles. Il effectue des scans de vulnérabilité réseau en exécutant des tests de sécurité et des scripts d'attaque réseau, ainsi qu'en menant des audits de sécurité locaux via des vérifications de version statiques des logiciels installés. Le projet utilise des flux gérés par la communauté pour synchroniser et mettre à jour les définitions de sécurité locales et les tests de vulnérabilité. Ces tests et configurations de scan sont chargés dans le système via des images de conteneurs ou des transferts manuels et stockés dans une base de données relationnelle persistante pour le suivi et le reporting à long terme. Le système inclut une stack de gestion qui peut être déployée via l'orchestration de conteneurs. Le contrôle administratif est fourni via un tableau de bord de gestion web, des outils en ligne de commande dédiés et diverses interfaces de procédure distante, incluant des API basées sur XML et Windows Management Instrumentation pour l'exécution de processus distants sur les systèmes Windows. La sécurité et l'accès sont gérés via le contrôle d'accès basé sur les rôles, l'application de politiques de mots de passe et le chiffrement TLS pour l'interface web. Le scanner propose également une planification de tâches asynchrone pour automatiser les audits de sécurité et prend en charge les notifications par email via SMTP pour les alertes de sécurité.

    Imports and updates vulnerability tests and compliance policies into persistent storage volumes.

    Rustcfoogreenbone
    Voir sur GitHub↗4,670
  • blocklistproject/listsAvatar de blocklistproject

    blocklistproject/Lists

    4,641Voir sur GitHub↗

    Lists is a curated collection of DNS blocklists, a domain blocklist generator, and a categorized library of domains used for network content filtering. The project provides a command-line pipeline that aggregates upstream sources to build and validate blocklists used to redirect unwanted traffic to null addresses. The project distinguishes itself through a CLI-driven build pipeline that automates the fetching, validation, and daily regeneration of datasets. It organizes domains into discrete functional categories rather than a single monolithic list and exports them in multiple syntaxes, incl

    Catalogs known fraudulent domains to prevent users from accessing sites associated with scams or malware.

    Pythonadblockadblock-listblocklist
    Voir sur GitHub↗4,641
  • strozfriedberg/windows-exploit-suggesterAvatar de strozfriedberg

    strozfriedberg/Windows-Exploit-Suggester

    4,211Voir sur GitHub↗

    Windows-Exploit-Suggester is a security analysis tool designed to audit patch levels and identify vulnerabilities on Windows hosts. It functions as a vulnerability scanner and patch level auditor that compares installed system hotfixes against Microsoft security bulletins to detect missing updates. The project maps these missing security updates to known public exploits and available Metasploit modules. It uses a vulnerability database interface to download and query external security bulletin data, linking specific unpatched vulnerabilities to viable exploit vectors. The tool's capabilities

    Synchronizes local vulnerability definitions by downloading and parsing security bulletins from remote sources.

    Python
    Voir sur GitHub↗4,211
  • gdssecurity/windows-exploit-suggesterAvatar de GDSSecurity

    GDSSecurity/Windows-Exploit-Suggester

    4,209Voir sur GitHub↗

    Windows-Exploit-Suggester est un outil d'audit de sécurité conçu pour scanner les systèmes Windows à la recherche de composants obsolètes et de correctifs de sécurité manquants. Il fonctionne comme un scanner de vulnérabilités qui compare les niveaux de correctifs cibles avec les bulletins de sécurité officiels des fournisseurs pour identifier les failles de sécurité. L'outil se spécialise dans le mapping d'exploits, reliant les mises à jour manquantes identifiées à du code d'exploitation public connu et à des modules de test d'intrusion disponibles. Il automatise le processus de recherche en croisant les correctifs manquants avec des identifiants de vulnérabilité spécifiques pour déterminer les vecteurs d'attaque applicables. Le système inclut des capacités de comparaison de niveau de correctif à distance et de détection heuristique pour déduire l'état d'un hôte. Il maintient sa précision grâce à un mécanisme de synchronisation qui télécharge et analyse les dernières données de sécurité provenant des sources des fournisseurs pour mettre à jour sa base de données de vulnérabilités interne.

    Updates local security definitions from remote vendor vulnerability sources to maintain accuracy.

    Python
    Voir sur GitHub↗4,209
  • x-cmd/x-cmdAvatar de x-cmd

    x-cmd/x-cmd

    4,037Voir sur GitHub↗

    x-cmd is an AI agent orchestrator, cloud infrastructure CLI, and cross-platform package manager that provides an enhanced POSIX shell toolkit. It integrates large language models directly into the terminal for chatting, code generation, and the execution of agentic workflows, while offering a framework for building interactive terminal user interface components. The project distinguishes itself by deploying containerized AI agents within isolated sandboxes, provisioning them with specialized skills and headless browser automation capabilities. It further streamlines development through a unif

    Monitors open-source vulnerabilities by cross-referencing against known exploited vulnerability catalogs.

    Shellagentaibash
    Voir sur GitHub↗4,037
  • scipag/vulscanAvatar de scipag

    scipag/vulscan

    3,761Voir sur GitHub↗

    Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection. The tool provides mechanisms for refining identification accuracy, including an interactive mode for manual version overriding and configurable matching logic to filter results. It manages security data through a system for loading local datasets and synchr

    Provides mechanisms for updating local security definitions from remote vulnerability sources.

    Lua
    Voir sur GitHub↗3,761
  • dependencytrack/dependency-trackAvatar de DependencyTrack

    DependencyTrack/dependency-track

    3,612Voir sur GitHub↗

    Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

    Synchronizes with external vulnerability databases and scoring systems to prioritize mitigation based on exploitability.

    Javaappsecbill-of-materialsbom
    Voir sur GitHub↗3,612
  • cve-search/cve-searchAvatar de cve-search

    cve-search/cve-search

    2,593Voir sur GitHub↗

    cve-search is a vulnerability search engine and database manager designed to index, synchronize, and query CVE and CPE security vulnerability data. It functions as a security data warehouse that imports vulnerability feeds into a local database to enable fast, keyword-based discovery of security flaws. The project provides a web-based vulnerability browser and a programmatic JSON API for retrieving records and risk scores. It utilizes full-text indexing for vulnerability descriptions and implements an identity-verified security portal using the OpenID Connect standard for user authentication.

    Loads and synchronizes security vulnerability records from remote sources into a local searchable database.

    Pythoncommon-vulnerabilitiescpecve
    Voir sur GitHub↗2,593
  • google/osv.devAvatar de google

    google/osv.dev

    2,494Voir sur GitHub↗

    OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability schema to track security flaws. It functions as a system for collecting and normalizing security data from diverse ecosystems into a single unified format, providing a web API for querying package vulnerabilities and submitting standardized records. The project distinguishes itself through a security advisory distribution service that supports bulk dataset exports via cloud storage buckets and incremental synchronization of security record updates. It also employs sandbox-bas

    Imports security records from public repositories, web APIs, or cloud storage buckets after validating they match a specific schema.

    Pythonsecuritysecurity-toolsvulnerability
    Voir sur GitHub↗2,494
  1. Home
  2. Security & Cryptography
  3. Vulnerability Scanning
  4. Vulnerability Data Synchronization

Explorer les sous-tags

  • Exploit Reference Aggregators1 sous-tagTools that centralize vulnerability details and their corresponding exploit references for research. **Distinct from Vulnerability Data Synchronization:** Distinct from Vulnerability Data Synchronization: focuses on the aggregation of researcher-centric references and PoCs