111 results for “topic:cwe”
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
cwe_checker finds vulnerable patterns in binary executables
The Correlated CVE Vulnerability And Threat Intelligence Database API
OSINT tool - gets data from services like shodan, censys etc. in one app
Generate MITRE ATT&CK and D3FEND from a list of CVEs. Database with CVE, CWE, CAPEC, MITRE ATT&CK and D3FEND Techniques data is updated daily. Showcased at BlackHat Europe 2025 Arsenal.
Collection of penetration test reports and pentest report templates. Published by the the best security companies in the world.
Corax for Java: A general static analysis framework for java code checking.
Vulnogram is the tool for reserving, managing, and publishing CVEs. Get started at vulnogram.org or deploy Docker edition for full enterprise features.
Open-Source Vulnerability Intelligence Center - Unified source of vulnerability, exploit and threat Intelligence feeds
The goal of this project is to provide additional features on top of the existing npm audit options
"Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting" by Erik Hemberg, Jonathan Kelly, Michal Shlapentokh-Rothman, Bryn Reinstadler, Katherine Xu, Nick Rutar, Una-May O'Reilly
Python API for vFeed Vulnerability & Threat Intelligence Database Enterprise & Pro Editions
Collection of CVEs from Sick Codes, or collaborations on https://sick.codes security research & advisories.
Repository for "SecurityEval Dataset: Mining Vulnerability Examples to Evaluate Machine Learning-Based Code Generation Techniques" published in MSR4P&S'22.
Open Source Tool - Cybersecurity Graph Database in Neo4j
A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.
Development of the NIST vulnerability data ontology (Vulntology).
WebGoat.NETCore - port of original WebGoat.NET to .NET Core
Daily archiver & triage issue creator for new releases of CISA's Known Exploited Vulnerabilities list
Juliet C/C++ Dynamic Test Suite
The Common Vulnerabilities Exposures (CVE) Database
A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC
AI-native security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
Sonarqube cloudformation plugin, IaC security supports cfn-nag/checkov
Severity scoring and exploit categorisation for vulnerability reports using machine-learning tools.
National Vulnerability Database (NVD) implemented by rust
CISA Known Exploited Vulnerabilities Catalog Enrichment
A search engine on information delivered by OSINT sources to support Vulnerability Assessment