awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Vulnerability Management and Tracking Systems

Ranking updated Jun 30, 2026

For a vulnerability management platform, the first results are infobyte/faraday (Faraday is a full-featured vulnerability management platform that aggregates findings from diverse security scanners into a single dashboard, tracks remediation, and analyzes risk, fitting this search for a centralized, open-source solution), wazuh/wazuh (Wazuh is a full-featured open-source security platform that provides vulnerability scanning, asset inventory, continuous monitoring, and dashboards, making it a strong fit for a centralized vulnerability management tool with remediation tracking and integrations) and yogeshojha/rengine (Rengine is an open-source vulnerability management platform that continuously monitors attack surfaces, discovers assets, runs vulnerability scans via plugins, and provides centralized tracking and reporting for remediation — fitting this search squarely). defectdojo/django-defectdojo and 1n3/sn1per round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

Automated platforms for continuously monitoring, identifying, and remediating security vulnerabilities across your digital infrastructure assets.

Vulnerability Management and Tracking Systems

Find the best repos with AI.We'll search the best matching repositories with AI.
  • infobyte/faradayinfobyte avatar

    infobyte/faraday

    6,523View on GitHub↗

    Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag

    Faraday is a full-featured vulnerability management platform that aggregates findings from diverse security scanners into a single dashboard, tracks remediation, and analyzes risk, fitting this search for a centralized, open-source solution.

    PythonRemediation TrackingSecurity Asset InventoriesAsset Inventory Aggregators
    View on GitHub↗6,523
  • wazuh/wazuhwazuh avatar

    wazuh/wazuh

    14,779View on GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Wazuh is a full-featured open-source security platform that provides vulnerability scanning, asset inventory, continuous monitoring, and dashboards, making it a strong fit for a centralized vulnerability management tool with remediation tracking and integrations.

    CVulnerability ScannersVulnerability Scanning
    View on GitHub↗14,779
  • yogeshojha/rengineyogeshojha avatar

    yogeshojha/rengine

    8,472View on GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    Rengine is an open-source vulnerability management platform that continuously monitors attack surfaces, discovers assets, runs vulnerability scans via plugins, and provides centralized tracking and reporting for remediation — fitting this search squarely.

    HTMLVulnerability Scanning
    View on GitHub↗8,472
  • defectdojo/django-defectdojoDefectDojo avatar

    DefectDojo/django-DefectDojo

    4,528View on GitHub↗

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The

    DefectDojo aggregates findings from multiple security scanners, normalizes them for prioritization, tracks remediation, and provides dashboards and reporting, making it a comprehensive open-source vulnerability management platform that fits your need for centralized, continuous monitoring and tracking.

    HTMLSecurity Finding Management
    View on GitHub↗4,528
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Sn1per is a vulnerability management platform that automates reconnaissance, scanning, and AI-powered analysis, with attack surface discovery and continuous monitoring, closely matching the need for a centralized detection and remediation tool.

    ShellFinding Classification
    View on GitHub↗10,049
  • shadow1ng/fscanshadow1ng avatar

    shadow1ng/fscan

    13,421View on GitHub↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    Fscan is an automated penetration testing and vulnerability assessment tool for internal network reconnaissance, which performs scanning and detection, but it is not a continuous vulnerability management platform with centralized remediation tracking, risk-based prioritization, or sustained monitoring and reporting features.

    GoVulnerability ScannersVulnerability Scanning
    View on GitHub↗13,421
  • future-architect/vulsfuture-architect avatar

    future-architect/vuls

    12,185View on GitHub↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Vuls is an agentless vulnerability scanner and CVE aggregator, but it is a scanning component rather than a full vulnerability management platform with built-in asset inventory, risk-based prioritization, remediation tracking, and centralized dashboards.

    GoVulnerability ScannersVulnerability Scanning
    View on GitHub↗12,185
  • zan8in/afrogzan8in avatar

    zan8in/afrog

    4,182View on GitHub↗

    afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify

    afrog is a powerful HTTP vulnerability scanner with PoC execution and fuzzing, but it is primarily a scanning tool rather than a full vulnerability management platform with asset inventory, remediation tracking, and integrated dashboards.

    GoVulnerability ScannersVulnerability Scanning
    View on GitHub↗4,182
  • armosec/kubescapearmosec avatar

    armosec/kubescape

    11,482View on GitHub↗

    Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of

    Kubescape is a powerful Kubernetes security scanner that detects vulnerabilities in container images and configurations, but it is limited to Kubernetes environments and does not cover the full range of assets (servers, cloud, networks) that a general vulnerability management platform should monitor and track.

    GoVulnerability ScannersVulnerability Scanning
    View on GitHub↗11,482
  • anthropics/claude-code-security-reviewanthropics avatar

    anthropics/claude-code-security-review

    5,316View on GitHub↗

    This project is an AI-powered static analysis tool and automated vulnerability scanner designed to detect security flaws such as injection and authentication bypasses. It uses large language models to perform semantic reasoning across multiple programming languages, identifying vulnerabilities within code changes. The tool operates as a GitHub Action that integrates into continuous integration pipelines to analyze pull request diffs. It focuses on modified lines of code to target new risks and reports findings by posting automated comments directly to the pull request. Analysis is directed b

    This is an AI-powered static analysis scanner that finds vulnerabilities in pull request diffs via a GitHub Action, but it lacks the asset inventory, continuous monitoring across all assets, risk-based prioritization, remediation tracking, and centralized dashboard that define a full vulnerability management platform.

    PythonVulnerability Scanners
    View on GitHub↗5,316
  • presidentbeef/brakemanpresidentbeef avatar

    presidentbeef/brakeman

    7,248View on GitHub↗

    Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us

    Brakeman is a static analysis security scanner for Ruby on Rails code, not a continuous vulnerability management platform—it scans code on demand rather than monitoring assets across an organization with inventory, prioritization, and remediation tracking.

    RubySecurity Finding ManagementSecurity ScannersVulnerability Scoring
    View on GitHub↗7,248
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Nuclei is a fast, template-driven vulnerability scanner that excels at automated detection, but it is not a centralized vulnerability management platform—it lacks built-in asset inventory, remediation tracking, and dashboards needed for continuous monitoring and prioritization across an organization.

    GoVulnerability ScannersVulnerability ScanningVulnerability Ticketing Integrators
    View on GitHub↗29,189
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
infobyte/faraday6.5KPythonGPL-3.0Jun 11, 2026
wazuh/wazuh14.8KCotherFeb 20, 2026
yogeshojha/rengine
8.5K
HTML
gpl-3.0
Nov 16, 2025
defectdojo/django-defectdojo4.5KHTMLbsd-3-clauseFeb 20, 2026
1n3/sn1per10KShellotherApr 29, 2026
shadow1ng/fscan13.4KGomitJan 31, 2026
future-architect/vuls12.2KGoGPL-3.0Jun 17, 2026
zan8in/afrog4.2KGomitFeb 20, 2026
armosec/kubescape11.5KGoApache-2.0Jun 17, 2026
anthropics/claude-code-security-review5.3KPythonMITFeb 11, 2026

Related searches

  • an open source scanner for security vulnerabilities
  • an automated security scanner for web applications
  • Vulnerability and Dependency Scanning
  • an intentionally vulnerable cloud environment for practice
  • a vulnerable web application for security training
  • a dynamic application security scanner
  • an open source vulnerability scanner for infrastructure
  • a container vulnerability scanner