Bookmarks
Tag cloud
Picture wall
Daily
RSS Feed
  • RSS Feed
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filters

Links per page

  • 20 links
  • 50 links
  • 100 links

Filters

Untagged links
9 results tagged vulnerabilities  ✕   ✕
OpenCVE https://www.opencve.io/
Tue 14 Dec 2021 04:50:54 PM PST archive.org

OpenCVE lets you search the CVE you want filtered by vendor, product, CVSS or CWE. Synchronized with the feed provided by the NVD. So each CVE displays the standards you already know (CVE, CPE, CWE, CVSS). You can then subscribe as many vendors or products as you want, and you will be notified as soon as a CVE concerning them is published or updated. Your custom dashboards and reports only include the CVEs associated with your subscriptions, and you can filter the list by keywords of CVSS score. OpenCVE keeps track of the changes, so you can find the history of your alerts in your Reports page. Can be self-hosted if you're concerned about leaking information outside of your organization.

REST API: https://docs.opencve.io/api/

Github: https://github.com/opencve/opencve

infosec vulnerabilities management reporting cve rest api glitch service webapp python selfhosted
inTheWild https://inthewild.io/
Thu 02 Dec 2021 03:58:23 PM PST archive.org

Community driven open database of vulnerability exploitation in the wild. We believe that exploitation information is about safety and it should be easy to access and not be behind paywalls. Get alerts on new reports of exploitation via RSS, Twitter, grab our docker image, the hourly database exports or get the full exploited list in the API.

infosec vulnerabilities reports triage rss rest api glitch exocortex
CVE https://cve.mitre.org/
Mon 26 Jul 2021 01:41:27 PM PDT archive.org

The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program. Partners publish CVE Records to communicate consistent descriptions of vulnerabilities. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.

infosec vulnerabilities cve feeds security
GitHub - roottusk/vapi: vAPI is a Vulnerable Adversely Programmed Interface which is Self-Hostable PHP Interface that demonstrates OWASP API Top 10 in the means of Exercises. https://github.com/roottusk/vapi
Thu 10 Sep 2020 06:58:33 PM PDT archive.org

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable PHP Interface that demonstrates OWASP API Top 10 in the means of Exercises. Requires PHP, Apache, MySQL, and probably a man-in-the-middle proxy.

php rest api infosec practice vulnerabilities
securego/gosec: Golang security checker https://github.com/securego/gosec
Mon 10 Sep 2018 11:09:06 AM PDT archive.org

Static security analyzer for Golang code. Checks against the Golang AST. Tries to verify some best practices (no hardcoded credentials, listening on 0.0.0.0 by default, things like that. Has all of the usual CLI options you'd hope it has.

golang infosec analyzer static vulnerabilities bestpractices cli
cve-search http://cve-search.org/
Sun 15 Apr 2018 11:11:55 PM PDT archive.org

Toolset to perform local searches for known vulnerabilities in the CVE database. Set up your own mirror or use their public API or RSS feed to run arbitrary searches.

F/OSS software that you can download, install, and use to set up your own mirror. Uses MongoDB, but nobody's perfect.

Maybe I can write a search plugin for Searx?

rss api vulnerabilities cve infosec search software
Exploits Database by Offensive Security http://www.exploit-db.com/
Tue 20 Mar 2018 01:44:32 AM PDT archive.org

Offensive Security Training has taken over where Milw0rm left off in their archival of live exploits, vulnerability descriptions, attacks, and whitepapers.

information exploits database infosec papers shellcode vulnerabilities
NVD - Home https://nvd.nist.gov/
Tue 20 Mar 2018 12:03:00 AM PDT archive.org

National Vulnerability Database.

infosec feeds vulnerabilities cve security
coreos/clair: Vulnerability Static Analysis for Containers https://github.com/coreos/clair
Mon 19 Mar 2018 11:38:07 PM PDT archive.org

Clair is a FOSS utility for conducting static security analysis of Linux containers, Docker containers in particular. Clair continually updates its internal index of known vulnerabilities so it can keep constant watch over what it monitors. Has a modular architecture to make it easier to extend the project without having to fork() it. Also designed to fit into a CI/CD pipeline to monitor in-house containers as they're built. Plugs into Kubernetes. Requires Postgres. Written in Go.  sysadmin infosec scanner scanning

scanning postgres vulnerabilities infosec analysis sysadmin linux golang security foss containers scanner
4219 links, including 279 private
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service by the Shaarli community - Theme by kalvn