An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with poc

A curated list of projects in awesome lists tagged with poc .

https://github.com/chaitin/xray

一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

passive-vulnerability-scanner poc security sqlinjection vulnerability vulnerability-scanner xss

Last synced: 28 Jan 2026

https://github.com/frohoff/ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

deserialization exploit gadget java javadeser jvm poc serialization vulnerability

Last synced: 14 May 2025

https://github.com/mr-xn/penetration_testing_poc

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

authentication-bypass bypass cobalt-strike csrf csrf-webshell cve cve-cms exploit getshell oa-getshell penetration-testing penetration-testing-poc php-bypass poc poc-exp rce sql-getshell sql-poc thinkphp

Last synced: 27 Jan 2026

https://github.com/Mr-xn/Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

authentication-bypass bypass cobalt-strike csrf csrf-webshell cve cve-cms exploit getshell oa-getshell penetration-testing penetration-testing-poc php-bypass poc poc-exp rce sql-getshell sql-poc thinkphp

Last synced: 13 Mar 2025

https://github.com/nomi-sec/poc-in-github

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

cve exploit poc security vulnerability

Last synced: 25 Jan 2026

https://github.com/nomi-sec/PoC-in-GitHub

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

cve exploit poc security vulnerability

Last synced: 30 Mar 2025

https://github.com/k8gege/k8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

0day brute-force bypass crack database exp exploit getshell hacking lpe netscan password pentest poc privilege-escalation rce scanner

Last synced: 13 May 2025

https://github.com/k8gege/K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

0day apt brute-force bypass crack database exploit getshell hacking netscan password pentest poc privilege-escalation scanner

Last synced: 30 Mar 2025

https://github.com/ffffffff0x/1earn

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup

blueteam collection ctf hacking ics-security infosec linux-learning markdown-article pentest pentest-tool poc post-penetration redteam security security-tools study writeup

Last synced: 14 May 2025

https://github.com/k8gege/ladon

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange

brute-force exp exploit getshell hack hacking ipscanner ladon netscan password pentest poc portscan scanner security security-scanner security-tools tools

Last synced: 15 May 2025

https://github.com/k8gege/Ladon

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange

brute-force exp exploit getshell hack hacking ipscanner ladon netscan password pentest poc portscan scanner security security-scanner security-tools tools

Last synced: 29 Apr 2025

https://github.com/threekiii/awesome-poc

一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.

poc

Last synced: 18 Feb 2026

https://github.com/zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340

cve-2020-10199 cve-2020-10204 cve-2020-11444 cve-2020-14882 cve-2020-1938 cve-2020-2551 cve-2020-2555 cve-2020-2883 cve-2020-5902 drupal exp exploit getshell nexus poc tomcat vulnerability weblogic webshell

Last synced: 15 May 2025

https://github.com/zan8in/afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.

afrog bug-bounty penetration-testing pentest poc red-teaming vulnerability-scanner vulnerability-scanning-tools

Last synced: 13 May 2025

https://github.com/wy876/POC

收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1100多个poc/exp,长期更新。

poc

Last synced: 05 Apr 2025

https://github.com/notselwyn/cve-2024-1086

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.

cve cve-2024-1086 exploit lpe poc

Last synced: 15 May 2025

https://github.com/Notselwyn/CVE-2024-1086

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.

cve cve-2024-1086 exploit lpe poc

Last synced: 26 Mar 2025

https://github.com/tr0uble-maker/poc-bomber

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

cve exp getshell poc poc-bomber rce redteam vulnerability-scanner

Last synced: 08 Oct 2025

https://github.com/tr0uble-mAker/POC-bomber

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

cve exp getshell poc poc-bomber rce redteam vulnerability-scanner

Last synced: 12 Jul 2025

https://github.com/ascotbe/medusa

:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

cobaltstrike cve dnslog email exp mail medusa metasploit-framework payload poc readteam virus xss

Last synced: 15 May 2025

https://github.com/Ascotbe/Medusa

:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

cobaltstrike cve dnslog email exp mail medusa metasploit-framework payload poc readteam virus xss

Last synced: 24 Mar 2025

https://github.com/k8gege/ladongo

Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBanner/HttpTitle/TcpBanner/Weblogic/Oxid多网卡主机,端口扫描服务识别PortScan。

bannerscan brute-force detection exploit ftpscan hacktools ms17010 mysqlscan poc portscan scanner security-tools smbscan sshscan

Last synced: 15 May 2025

https://github.com/MatheuZSecurity/Singularity

Stealthy Linux Kernel Rootkit for modern kernels (6x)

ftrace hidden hooking kernel linux lkm poc rootkit syscall

Last synced: 01 May 2026

https://github.com/k8gege/LadonGo

Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBanner/HttpTitle/TcpBanner/Weblogic/Oxid多网卡主机,端口扫描服务识别PortScan。

bannerscan brute-force detection exploit ftpscan hacktools ms17010 mysqlscan poc portscan scanner security-tools smbscan sshscan

Last synced: 11 Jul 2025

https://github.com/baizesec/bylibrary

白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目

baize exp poc sec security

Last synced: 28 Jan 2026

https://github.com/lucifer1993/angelsword

Python3编写的CMS漏洞检测框架

cms poc vulnerability-scanners

Last synced: 08 Apr 2025

https://github.com/Lucifer1993/AngelSword

Python3编写的CMS漏洞检测框架

cms poc vulnerability-scanners

Last synced: 13 Mar 2025

https://github.com/BaizeSec/bylibrary

白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目

baize exp poc sec security

Last synced: 11 Jul 2025

https://github.com/c0ny1/fastjsonexploit

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

exp exploiting-vulnerabilities fastjson poc

Last synced: 16 May 2025

https://github.com/c0ny1/FastjsonExploit

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

exp exploiting-vulnerabilities fastjson poc

Last synced: 13 Mar 2025

https://github.com/danigargu/CVE-2020-0796

CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost

coronablue cve-2020-0796 exploit poc smbghost

Last synced: 11 Jul 2025

https://github.com/k8gege/k8cscan

K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动

cobalt-strike crack exploit ftp getshell hacking ipc mssql mysql netscan oracle password pentest poc portscan scanner security smb subdomain wmi

Last synced: 16 May 2025

https://github.com/k8gege/K8CScan

K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动

cobalt-strike crack exploit ftp getshell hacking ipc mssql mysql netscan oracle password pentest poc portscan scanner security smb subdomain wmi

Last synced: 13 Mar 2025

https://github.com/adysec/nuclei_poc

Nuclei POC,每日更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现。已有19w+POC,已校验格式的有效性并去重(验证的是格式的有效性)

daily exploit exploits fingerprint hack-tools hacker hacking nuclei nuclei-templates poc scanner security security-scanner

Last synced: 16 May 2025

https://github.com/tenable/poc

Proof of Concepts

poc

Last synced: 14 May 2025

https://github.com/bit4woo/Fiora

Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。

burp-extensions fiora nuclei nuclei-gui poc

Last synced: 11 Jul 2025

https://github.com/bit4woo/fiora

Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。

burp-extensions fiora nuclei nuclei-gui poc

Last synced: 16 May 2025

https://github.com/1n7erface/poclist

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE

alibaba-nacos jar poc

Last synced: 16 May 2025

https://github.com/arthepsy/CVE-2021-4034

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)

cve cve-2021-4034 poc

Last synced: 04 Apr 2025

https://github.com/1n7erface/template

Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描

poc scanner security-tools

Last synced: 28 Jan 2026

https://github.com/arthepsy/cve-2021-4034

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)

cve cve-2021-4034 poc

Last synced: 16 May 2025

https://github.com/1n7erface/Template

Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描

poc scanner security-tools

Last synced: 07 Sep 2025

https://github.com/ycdxsb/PocOrExp_in_Github

Automatically Collect POC or EXP from GitHub by CVE ID. If you are unable to find the POC/EXP on GitHub, you can also check here: https://pocorexps.nsa.im/

cve exploit poc vulnerabilities

Last synced: 12 Jul 2025

https://github.com/tenable/routeros

RouterOS Security Research Tooling and Proof of Concepts

bughunting exploits honeypot poc routeros scanner

Last synced: 25 Mar 2025

https://github.com/100apps/charles-hacking

Hacking Charles Web Debugging Proxy

do-not-use-in-production just-for-learn poc

Last synced: 27 Jan 2026

https://github.com/StarCrossPortal/scalpel

scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。

cve exploits fuzzing poc scanner vulnerabilities vulnerability

Last synced: 11 Jul 2025

https://github.com/vulscanteam/vulscan

vulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...

exploit-databa exploitation-framework poc pocscan pocscanner scanner-web security-tools sesecurity-vulnerability vulnerability vulnerability-database-entry vulnerability-databases vulnerability-scanners vulnerability-scanning vulscan webscan webscanner

Last synced: 02 Apr 2025

https://github.com/yqcs/prismx

:: Prism X · Automated Enterprise Network Security Risk Detection and Vulnerability Scanning Tool / 棱镜 X · 自动化企业网络安全风险检测、漏洞扫描工具

appscan awvs exp fscan goby nessus nuclei poc prismx vulnerability webscanner

Last synced: 09 Apr 2025

https://github.com/dreadlocked/drupalgeddon2

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

cve-2018-7600 drupal drupal7 drupal8 drupalgeddon drupalgeddon2 exploit poc sa-core-2018-002

Last synced: 04 Apr 2025

https://github.com/CHYbeta/cmsPoc

CMS渗透测试框架-A CMS Exploit Framework

cms discuzx drupal phpcms poc security

Last synced: 11 Jul 2025

https://github.com/chybeta/cmspoc

CMS渗透测试框架-A CMS Exploit Framework

cms discuzx drupal phpcms poc security

Last synced: 05 Apr 2025

https://github.com/jamf/CVE-2020-0796-RCE-POC

CVE-2020-0796 Remote Code Execution POC

cve-2020-0796 poc rce remote-code-execution smbghost

Last synced: 07 Sep 2025

https://github.com/raphaelsc/am-i-affected-by-meltdown

Meltdown Exploit / Proof-of-concept / checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.

exploit intelbug kaiser kpti meltdown poc pti security

Last synced: 05 Apr 2025

https://github.com/raphaelsc/Am-I-affected-by-Meltdown

Meltdown Exploit / Proof-of-concept / checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.

exploit intelbug kaiser kpti meltdown poc pti security

Last synced: 21 Apr 2025

https://github.com/komomon/Komo

🚀Komo, a comprehensive asset collection and vulnerability scanning tool. Komo 一个综合资产收集和漏洞扫描工具,集成了20余款工具,通过多种方式对子域进行获取,收集域名邮箱,进行存活探测,域名指纹识别,域名反查ip,ip端口扫描,web服务链接爬取并发送给xray,对web服务进行POC漏洞扫描,对主机进行主机漏洞扫描。

amass bugbounty crawlergo ctfr emailall gospider hacking httpx information-gathering infosec ksubdomain naabu nuclei oneforall osint pentesting poc rad subfinder xray

Last synced: 12 Jul 2025

https://github.com/chushuai/wscan

Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.

cel-go chromedp crawler headless martian passive-vulnerability-scanner poc sql-injection subdomains testwaf vulnerability-scanner waf webscan wscan xss

Last synced: 11 Jul 2025

https://github.com/xnbox/DeepfakeHTTP

DeepfakeHTTP is a web server that uses HTTP dumps as a source for responses.

api demo dummy dump graphql http http-server mock mocks-server poc qa qa-automation rest rest-api restful-api spies stub test-automation testing testing-tools

Last synced: 02 Apr 2025

https://github.com/joaomatosf/javadeserh2hc

Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).

deserialization java javadeser jboss jvm lab poc reverse-shell vulnerability

Last synced: 13 May 2025

https://github.com/joaomatosf/JavaDeserH2HC

Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).

deserialization java javadeser jboss jvm lab poc reverse-shell vulnerability

Last synced: 12 Mar 2025

https://github.com/ojasookert/CVE-2017-0785

Blueborne CVE-2017-0785 Android information leak vulnerability

blueborne cve-2017-0785 exploit poc

Last synced: 11 Jul 2025

https://github.com/1n3/wordpress-xmlrpc-brute-force-exploit

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

0day exploit poc wordpress wordpress-xmlrpc xml-rpc

Last synced: 04 Apr 2025

https://github.com/1N3/Wordpress-XMLRPC-Brute-Force-Exploit

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

0day exploit poc wordpress wordpress-xmlrpc xml-rpc

Last synced: 09 Jul 2025

https://github.com/xsscx/fuzz

Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT

burp burpsuite exploit fuzzing header html http injection injection-signatures input javascript malicious poc random rce xss

Last synced: 16 May 2026

https://github.com/ele7enxxh/poc-exp

poc or exp of android vulnerability

poc

Last synced: 13 May 2025

https://github.com/xsscx/commodity-injection-signatures

Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT

burp burpsuite exploit fuzzing header html http injection injection-signatures input javascript malicious poc random rce xss

Last synced: 05 Apr 2025

https://github.com/xsscx/Commodity-Injection-Signatures

Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT

burp burpsuite exploit fuzzing header html http injection injection-signatures input javascript malicious poc random rce xss

Last synced: 11 Jul 2025

https://github.com/k8gege/CVE-2019-0708

3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)

3389 cve-2019-0708 exp exploit hacking k8cscan pentest poc rdp security

Last synced: 13 Mar 2025

https://github.com/k8gege/cve-2019-0708

3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)

3389 cve-2019-0708 exp exploit hacking k8cscan pentest poc rdp security

Last synced: 06 Apr 2025

https://github.com/VoidSec/CVE-2020-1472

Exploit Code for CVE-2020-1472 aka Zerologon

cve-2020 exploit n-day poc voidsec zerologon

Last synced: 11 Jul 2025

https://github.com/voidsec/cve-2020-1472

Exploit Code for CVE-2020-1472 aka Zerologon

cve-2020 exploit n-day poc voidsec zerologon

Last synced: 06 Apr 2025

https://github.com/bytecode77/self-morphing-csharp-binary

Executable that mutates its own code

csharp poc

Last synced: 08 Apr 2025

https://github.com/orleven/Tentacle

Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.

exploit-framework fofa poc poc-script poc-vulnerability-verification shodan tentacle

Last synced: 11 Jul 2025

https://github.com/orleven/tentacle

Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.

exploit-framework fofa poc poc-script poc-vulnerability-verification shodan tentacle

Last synced: 05 Apr 2025

https://github.com/unclecheng-li/poc-lab

Recent CVE PoC & reproduction scripts. Focused on high-severity vulnerabilities across Linux kernel, Windows, macOS and more.

c cybersecurity linux poc python python3 vulnerability

Last synced: 27 May 2026

https://github.com/jiangsir404/POC-S

POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC

cnvd-2020-10487 dnslog pentest-scripts poc poc-t pocs pocsuite tomcat-ajp-lfi

Last synced: 11 Jul 2025

https://github.com/hktalent/spring-spel-0day-poc

spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963

0day cve-2022-22963 exp java poc rce spel spring spring-cloud-function

Last synced: 06 Apr 2025

https://github.com/a2u/cve-2018-7600

💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002

cve-2018-7600 drupal drupalgeddon2 exploit poc sa-core-2018-002

Last synced: 06 Apr 2025

https://github.com/bytecode77/living-off-the-land

Fileless attack with persistence

fileless fileless-attack poc

Last synced: 16 May 2025

https://github.com/hanc00l/some_pocsuite

用于漏洞排查的pocsuite3验证POC代码

poc pocsuite

Last synced: 11 Jul 2025

https://github.com/TeraSecTeam/ary

Ary 是一个集成类工具,主要用于调用各种安全工具,从而形成便捷的一键式渗透。

automation penetration-testing pentest poc sqlinjection vulnerability vulnerability-scanners xss

Last synced: 11 Jul 2025

https://github.com/Yong-An-Dang/nuclei-plus

Functional enhancement based on nuclei. 基于 nuclei 的功能增强。

ai allinone editor nuclei nuclei-plus plugin-system poc template

Last synced: 07 Sep 2025

https://github.com/adamyordan/cve-2019-1003000-jenkins-rce-poc

Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)

cve cve-2019-1003000 exploit groovy information-security jenkins poc rce security security-1266

Last synced: 13 Oct 2025

https://github.com/guillaumefalourd/poc-github-actions

Various proofs of concept examples using Github Actions 🤖

beginners examples github-actions poc proof-of-concept workflows

Last synced: 16 May 2025