awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to projectdiscovery/cvemap

Open-source alternatives to Cvemap

30 open-source projects similar to projectdiscovery/cvemap, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Cvemap alternative.

  • techgaun/github-dorkstechgaun avatar

    techgaun/github-dorks

    3,140View on GitHub↗

    This project is a GitHub secret scanner and dorking tool designed to identify leaked credentials and private keys within repositories. It functions as an API reconnaissance utility that uses curated search queries and automated dorks to locate sensitive data across public and enterprise GitHub instances. The tool enables security vulnerability research and enterprise auditing by targeting both public cloud instances and private enterprise installations via configurable base URLs. It utilizes token-based authentication to access private repository content and bypass API rate limits. The syste

    Pythondorkdorkergithub-dork
    View on GitHub↗3,140
  • daffainfo/allaboutbugbountydaffainfo avatar

    daffainfo/AllAboutBugBounty

    6,644View on GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    View on GitHub↗6,644
  • kathanp19/howtohuntKathanP19 avatar

    KathanP19/HowToHunt

    7,146View on GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    bugbountybugbountytipsbughunting-methodology
    View on GitHub↗7,146

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • blacknon/pydorkblacknon avatar

    blacknon/pydork

    88View on GitHub↗

    Scraping and listing text and image searches on Google, Bing, DuckDuckGo, Baidu, Yahoo japan.

    Python
    View on GitHub↗88
  • chalker/notesChALkeR avatar

    ChALkeR/notes

    1,277View on GitHub↗

    Some public notes

    View on GitHub↗1,277
  • channyein1337/jsleakchannyein1337 avatar

    channyein1337/jsleak

    589View on GitHub↗

    jsleak is a tool to find secret , paths or links in the source code during the recon.

    Go
    View on GitHub↗589
  • c3n7ral051nt4g3ncy/webosintC3n7ral051nt4g3ncy avatar

    C3n7ral051nt4g3ncy/webosint

    344View on GitHub↗

    W3b0s1nt (WebOSINT) is a Python tool/script for passive Domain Intelligence gathering.

    Python
    View on GitHub↗344
  • harleo/knockknockharleo avatar

    harleo/knockknock

    190View on GitHub↗

    A simple reverse whois lookup tool which returns a list of domains owned by people or companies

    Go
    View on GitHub↗190
  • danielmiessler/seclistsdanielmiessler avatar

    danielmiessler/SecLists

    71,596View on GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHP
    View on GitHub↗71,596
  • drew-alleman/datasurgeonDrew-Alleman avatar

    Drew-Alleman/DataSurgeon

    899View on GitHub↗

    Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

    Rustbug-bountyctf-toolscybersecurity
    View on GitHub↗899
  • dwisiswant0/go-dorkdwisiswant0 avatar

    dwisiswant0/go-dork

    1,284View on GitHub↗

    The fastest dork scanner written in Go.

    Go
    View on GitHub↗1,284
  • edoverflow/bugbounty-cheatsheetEdOverflow avatar

    EdOverflow/bugbounty-cheatsheet

    6,498View on GitHub↗

    This project is a bug bounty resource directory, vulnerability research cheatsheet, and web security payload library. It serves as a centralized collection of curated payloads and common attack vectors used to identify security vulnerabilities in web applications. The repository provides a directory of platforms, books, and tools to support vulnerability discovery skills. It includes a reference for tested payloads and techniques used to trigger bugs and identify vulnerabilities during security audits. The content covers web application pentesting, security vulnerability testing, and general

    View on GitHub↗6,498
  • elvanderb/tcp-32764elvanderb avatar

    elvanderb/TCP-32764

    1,290View on GitHub↗

    some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G.

    Python
    View on GitHub↗1,290
  • friendsofphp/security-advisoriesFriendsOfPHP avatar

    FriendsOfPHP/security-advisories

    2,128View on GitHub↗

    PHP Security Advisories Database

    PHP
    View on GitHub↗2,128
  • hakluke/hakrawlerhakluke avatar

    hakluke/hakrawler

    4,993View on GitHub↗

    Hakrawler is a command-line web spider tool designed for security reconnaissance, built to crawl target websites and extract hyperlinks along with JavaScript file references. As a focused reconnaissance utility, it collects every discoverable URL and script source from a given domain, mapping the attack surface for penetration testing and vulnerability assessment. The tool differentiates itself through its concurrent architecture: a fixed-size goroutine pool fetches pages in parallel, while CSS selectors parse HTML to extract anchor and script references. A depth-aware recursion limiter preve

    Gobugbountycrawlinghacking
    View on GitHub↗4,993
  • googleprojectzero/ios-messaging-toolsgoogleprojectzero avatar

    googleprojectzero/iOS-messaging-tools

    383View on GitHub↗

    This repository contains several tools Project Zero uses to test iPhone messaging. It includes:

    Python
    View on GitHub↗383
  • d3ext/aortD

    D3Ext/AORT

    0View on GitHub↗
    View on GitHub↗0
  • hasecuritysolutions/vulnwhispererH

    HASecuritySolutions/VulnWhisperer

    0View on GitHub↗
    View on GitHub↗0
  • hktalent/scan4allhktalent avatar

    hktalent/scan4all

    6,127View on GitHub↗

    scan4all is an all-in-one vulnerability scanner that orchestrates parallel network reconnaissance, service cracking, and exploit execution across a wide range of protocols. It combines port discovery, web fingerprinting, password cracking, and a plugin-based database of over 15,000 proof-of-concept exploits into a single automated pipeline, with results streamed to Elasticsearch for structured querying and analysis. The tool distinguishes itself through its multi-engine orchestration, coordinating tools like nmap, naabu, and nuclei under one pipeline to avoid redundant work and share results.

    Go
    View on GitHub↗6,127
  • hueristiq/xurlfind3rhueristiq avatar

    hueristiq/xurlfind3r

    704View on GitHub↗

    A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.

    Go
    View on GitHub↗704
  • intel/cve-bin-toolintel avatar

    intel/cve-bin-tool

    1,702View on GitHub↗

    The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

    Python
    View on GitHub↗1,702
  • itm4n/perfusionI

    itm4n/Perfusion

    0View on GitHub↗
    View on GitHub↗0
  • itm4n/usodllloaderI

    itm4n/UsoDllLoader

    0View on GitHub↗
    View on GitHub↗0
  • ivanglinkin/fast-google-dorks-scanIvanGlinkin avatar

    IvanGlinkin/Fast-Google-Dorks-Scan

    1,729View on GitHub↗

    The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the specific web-site: common admin panels, the widespread file types and path traversal. The 100% automated.

    Shell
    View on GitHub↗1,729
  • j3ssie/cdnstripj3ssie avatar

    j3ssie/cdnstrip

    80View on GitHub↗

    Striping CDN & WAF IPs from a list of IP Addresses

    Go
    View on GitHub↗80
  • jakewnuk/sicknerdJ

    JakeWnuk/SickNerd

    0View on GitHub↗
    View on GitHub↗0
  • bnagy/crashwalkbnagy avatar

    bnagy/crashwalk

    361View on GitHub↗

    Crashwalk

    Go
    View on GitHub↗361
  • kostas-pa/lfitesterkostas-pa avatar

    kostas-pa/LFITester

    112View on GitHub↗

    LFITester is a Python3 program that automates the detection and exploitation of Local File Inclusion (LFI) vulnerabilities on a server.

    Python
    View on GitHub↗112
  • mr-robert0/logsensorMr-Robert0 avatar

    Mr-Robert0/Logsensor

    519View on GitHub↗

    A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanning

    Python
    View on GitHub↗519
  • balgogan/dorkscannerB

    Balgogan/dorkscanner

    0View on GitHub↗
    View on GitHub↗0