Skip to content
Change the repository type filter

All

    Repositories list

    • Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol vulnerability campaign impacting react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, and RSC-enabled frameworks like Next.js.
      Python
      0001Updated Dec 9, 2025Dec 9, 2025
    • DefectDojo is an open-source application vulnerability correlation and security orchestration tool.
      HTML
      1.8k0076Updated Dec 8, 2025Dec 8, 2025
    • A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode
      Python
      2520041Updated Dec 8, 2025Dec 8, 2025
    • Explanation and full RCE PoC for CVE-2025-55182
      Python
      151101Updated Dec 6, 2025Dec 6, 2025
    • Java web common vulnerabilities and security code which is base on springboot and spring security
      Java
      7580049Updated Dec 2, 2025Dec 2, 2025
    • Utils

      Public
      Phoenix Security Script and Utilities
      HTML
      0101Updated Nov 27, 2025Nov 27, 2025
    • TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
      HCL
      5.6k008Updated Nov 27, 2025Nov 27, 2025
    • Script to verify if Shai Hulud and Sha1-Hulud NPM package alike are affecting your NPM Build - check https://phoenix.security/shai-hulud-second-coming-npms-biggest-supply-chain-breach/
      Python
      21201Updated Nov 26, 2025Nov 26, 2025
    • CVNA
      JavaScript
      23005Updated Nov 26, 2025Nov 26, 2025
    • CSS
      5003Updated Nov 21, 2025Nov 21, 2025
    • notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
      Go
      239005Updated Nov 21, 2025Nov 21, 2025
    • Python 3 compatible repo of Tiredful API
      Python
      10004Updated Nov 21, 2025Nov 21, 2025
    • Quick Set of vulnerability tool for Qxi-npm-compromise-checker
      Python
      31701Updated Nov 18, 2025Nov 18, 2025
    • PYRUS is Phoenix Security’s YAML-native CMDB automation framework that unifies asset ownership, vulnerability attribution, and business alignment across DevSecOps. It replaces static CMDBs with metadata-driven synchronization from CI/CD, repositories, cloud, and identity systems to reflect the real state of your environment
      Python
      0100Updated Nov 17, 2025Nov 17, 2025
    • A Broken Application - Very Vulnerable!
      TypeScript
      303006Updated Nov 8, 2025Nov 8, 2025
    • A sample web application using Node.js, Express and Angular that is vulnerable to common security vulnerabilities.
      JavaScript
      53002Updated Nov 8, 2025Nov 8, 2025
    • The aim of the project is to develop intentionally vulnerable source code in various languages.
      HTML
      500630Updated Nov 6, 2025Nov 6, 2025
    • Mirror of broken crystals, but with specific dockerfiles for easy docker compose
      TypeScript
      5002Updated Nov 3, 2025Nov 3, 2025
    • HTML
      3001Updated Nov 1, 2025Nov 1, 2025
    • Legacy WebGoat 6.0 - Deliberately insecure JavaEE application
      Java
      4130047Updated Nov 1, 2025Nov 1, 2025
    • vulnado

      Public
      Purposely vulnerable Java application to help lead secure coding workshops
      Java
      819099Updated Nov 1, 2025Nov 1, 2025
    • Sample source code containing vulnerabilities to illustrate Fortify usage
      Java
      30002Updated Nov 1, 2025Nov 1, 2025
    • NIVA is a simple web application which is intentionally vulnerable to NoSQL injection. The purpose of this project is to facilitate a better understanding of the NoSQL injection vulnerability among a wide audience of software engineers, security engineers, pentesters, and trainers.
      Java
      25002Updated Nov 1, 2025Nov 1, 2025
    • javaspringvulny - a Spring Boot web application built wrong on purpose
      Java
      253101Updated Nov 1, 2025Nov 1, 2025
    • Damn Vulnerable C# Application (API)
      C#
      281003Updated Nov 1, 2025Nov 1, 2025
    • JavaScript
      365003Updated Nov 1, 2025Nov 1, 2025
    • JavaScript
      3002Updated Nov 1, 2025Nov 1, 2025
    • PHP
      7001Updated Nov 1, 2025Nov 1, 2025
    • Vulnerable API for educational purposes
      C#
      77000Updated Nov 1, 2025Nov 1, 2025
    • XSS Vulnerable code examples for you to practice locally.
      Hack
      3000Updated Nov 1, 2025Nov 1, 2025