Projects in Awesome Lists tagged with poc
A curated list of projects in awesome lists tagged with poc .
https://github.com/chaitin/xray
一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
passive-vulnerability-scanner poc security sqlinjection vulnerability vulnerability-scanner xss
Last synced: 28 Jan 2026
https://github.com/frohoff/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
deserialization exploit gadget java javadeser jvm poc serialization vulnerability
Last synced: 14 May 2025
https://github.com/trickest/cve
Gather and update all available and newest CVEs with their PoC.
cve cve-poc exploit hacking infosec latest-cve penetration-testing pentesting poc red-team security security-tools software-security software-vulnerabilities software-vulnerability vulnerabilities vulnerability
Last synced: 17 Feb 2026
https://github.com/mr-xn/penetration_testing_poc
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
authentication-bypass bypass cobalt-strike csrf csrf-webshell cve cve-cms exploit getshell oa-getshell penetration-testing penetration-testing-poc php-bypass poc poc-exp rce sql-getshell sql-poc thinkphp
Last synced: 27 Jan 2026
https://github.com/Mr-xn/Penetration_Testing_POC
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
authentication-bypass bypass cobalt-strike csrf csrf-webshell cve cve-cms exploit getshell oa-getshell penetration-testing penetration-testing-poc php-bypass poc poc-exp rce sql-getshell sql-poc thinkphp
Last synced: 13 Mar 2025
https://github.com/nomi-sec/poc-in-github
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
cve exploit poc security vulnerability
Last synced: 25 Jan 2026
https://github.com/nomi-sec/PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
cve exploit poc security vulnerability
Last synced: 30 Mar 2025
https://github.com/k8gege/k8tools
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
0day brute-force bypass crack database exp exploit getshell hacking lpe netscan password pentest poc privilege-escalation rce scanner
Last synced: 13 May 2025
https://github.com/k8gege/K8tools
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
0day apt brute-force bypass crack database exploit getshell hacking netscan password pentest poc privilege-escalation scanner
Last synced: 30 Mar 2025
https://github.com/ffffffff0x/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
blueteam collection ctf hacking ics-security infosec linux-learning markdown-article pentest pentest-tool poc post-penetration redteam security security-tools study writeup
Last synced: 14 May 2025
https://github.com/k8gege/ladon
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange
brute-force exp exploit getshell hack hacking ipscanner ladon netscan password pentest poc portscan scanner security security-scanner security-tools tools
Last synced: 15 May 2025
https://github.com/k8gege/Ladon
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange
brute-force exp exploit getshell hack hacking ipscanner ladon netscan password pentest poc portscan scanner security security-scanner security-tools tools
Last synced: 29 Apr 2025
https://github.com/threekiii/awesome-poc
一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
Last synced: 18 Feb 2026
https://github.com/zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
cve-2020-10199 cve-2020-10204 cve-2020-11444 cve-2020-14882 cve-2020-1938 cve-2020-2551 cve-2020-2555 cve-2020-2883 cve-2020-5902 drupal exp exploit getshell nexus poc tomcat vulnerability weblogic webshell
Last synced: 15 May 2025
https://github.com/zan8in/afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.
afrog bug-bounty penetration-testing pentest poc red-teaming vulnerability-scanner vulnerability-scanning-tools
Last synced: 13 May 2025
https://github.com/wy876/POC
收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1100多个poc/exp,长期更新。
Last synced: 05 Apr 2025
https://github.com/notselwyn/cve-2024-1086
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
cve cve-2024-1086 exploit lpe poc
Last synced: 15 May 2025
https://github.com/Notselwyn/CVE-2024-1086
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
cve cve-2024-1086 exploit lpe poc
Last synced: 26 Mar 2025
https://github.com/tr0uble-maker/poc-bomber
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
cve exp getshell poc poc-bomber rce redteam vulnerability-scanner
Last synced: 08 Oct 2025
https://github.com/tr0uble-mAker/POC-bomber
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
cve exp getshell poc poc-bomber rce redteam vulnerability-scanner
Last synced: 12 Jul 2025
https://github.com/ascotbe/medusa
:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中
cobaltstrike cve dnslog email exp mail medusa metasploit-framework payload poc readteam virus xss
Last synced: 15 May 2025
https://github.com/Ascotbe/Medusa
:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中
cobaltstrike cve dnslog email exp mail medusa metasploit-framework payload poc readteam virus xss
Last synced: 24 Mar 2025
https://github.com/k8gege/ladongo
Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBanner/HttpTitle/TcpBanner/Weblogic/Oxid多网卡主机,端口扫描服务识别PortScan。
bannerscan brute-force detection exploit ftpscan hacktools ms17010 mysqlscan poc portscan scanner security-tools smbscan sshscan
Last synced: 15 May 2025
https://github.com/k8gege/LadonGo
Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBanner/HttpTitle/TcpBanner/Weblogic/Oxid多网卡主机,端口扫描服务识别PortScan。
bannerscan brute-force detection exploit ftpscan hacktools ms17010 mysqlscan poc portscan scanner security-tools smbscan sshscan
Last synced: 11 Jul 2025
https://github.com/lucifer1993/angelsword
Python3编写的CMS漏洞检测框架
cms poc vulnerability-scanners
Last synced: 08 Apr 2025
https://github.com/Lucifer1993/AngelSword
Python3编写的CMS漏洞检测框架
cms poc vulnerability-scanners
Last synced: 13 Mar 2025
https://github.com/jweny/pocassist
傻瓜式漏洞PoC测试框架
cve penetration-testing-poc poc pocassist security security-tools vulnerability vulnerability-scanners
Last synced: 07 Oct 2025
https://github.com/c0ny1/fastjsonexploit
Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)
exp exploiting-vulnerabilities fastjson poc
Last synced: 16 May 2025
https://github.com/c0ny1/FastjsonExploit
Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)
exp exploiting-vulnerabilities fastjson poc
Last synced: 13 Mar 2025
https://github.com/danigargu/CVE-2020-0796
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
coronablue cve-2020-0796 exploit poc smbghost
Last synced: 11 Jul 2025
https://github.com/k8gege/k8cscan
K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动
cobalt-strike crack exploit ftp getshell hacking ipc mssql mysql netscan oracle password pentest poc portscan scanner security smb subdomain wmi
Last synced: 16 May 2025
https://github.com/k8gege/K8CScan
K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动
cobalt-strike crack exploit ftp getshell hacking ipc mssql mysql netscan oracle password pentest poc portscan scanner security smb subdomain wmi
Last synced: 13 Mar 2025
https://github.com/adysec/nuclei_poc
Nuclei POC,每日更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现。已有19w+POC,已校验格式的有效性并去重(验证的是格式的有效性)
daily exploit exploits fingerprint hack-tools hacker hacking nuclei nuclei-templates poc scanner security security-scanner
Last synced: 16 May 2025
https://github.com/bit4woo/Fiora
Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。
burp-extensions fiora nuclei nuclei-gui poc
Last synced: 11 Jul 2025
https://github.com/x364e3ab6/DudeSuite
DudeSuite Web Security Tools
0day 1day awvs dude dudesuite hacker hackertools hydra nday nmap packet penetration-testing-tools poc scan scanner-web sqlmap tools
Last synced: 07 Sep 2025
https://github.com/bit4woo/fiora
Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。
burp-extensions fiora nuclei nuclei-gui poc
Last synced: 16 May 2025
https://github.com/lucifer1993/satansword
红队综合渗透框架
fingerprinting pentest-tool poc security-tools vulnerability-detection vulnerability-scanners
Last synced: 16 May 2025
https://github.com/Lucifer1993/SatanSword
红队综合渗透框架
fingerprinting pentest-tool poc security-tools vulnerability-detection vulnerability-scanners
Last synced: 11 Jul 2025
https://github.com/1n7erface/poclist
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE
Last synced: 16 May 2025
https://github.com/arthepsy/CVE-2021-4034
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
Last synced: 04 Apr 2025
https://github.com/1n7erface/template
Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描
Last synced: 28 Jan 2026
https://github.com/arthepsy/cve-2021-4034
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
Last synced: 16 May 2025
https://github.com/1n7erface/Template
Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描
Last synced: 07 Sep 2025
https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
bugbounttips bugbounty bugbounty-writeups cve cve-2021-44228 cve-2021-45046 cve-2021-45105 cybersecurity exploit hacking log4j payload pentest pentesting poc red-team security security-writeups writeups
Last synced: 15 May 2025
https://github.com/puliczek/cve-2021-44228-poc-log4j-bypass-words
🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
bugbounttips bugbounty bugbounty-writeups cve cve-2021-44228 cve-2021-45046 cve-2021-45105 cybersecurity exploit hacking log4j payload pentest pentesting poc red-team security security-writeups writeups
Last synced: 13 Apr 2025
https://github.com/ycdxsb/PocOrExp_in_Github
Automatically Collect POC or EXP from GitHub by CVE ID. If you are unable to find the POC/EXP on GitHub, you can also check here: https://pocorexps.nsa.im/
cve exploit poc vulnerabilities
Last synced: 12 Jul 2025
https://github.com/puliczek/awesome-list-of-secrets-in-environment-variables
🦄🔒 Awesome list of secrets in environment variables 🖥️
blue-team bugbounttips bugbounty cve-2021-44228 cybersecurity exploit log4j pentesting poc red-team security security-writeups writeups
Last synced: 27 Jan 2026
https://github.com/tenable/routeros
RouterOS Security Research Tooling and Proof of Concepts
bughunting exploits honeypot poc routeros scanner
Last synced: 25 Mar 2025
https://github.com/100apps/charles-hacking
Hacking Charles Web Debugging Proxy
do-not-use-in-production just-for-learn poc
Last synced: 27 Jan 2026
https://github.com/thezdi/PoC
Proofs-of-concept
advantech cve-2016-0856 exploit poc proof-of-concept research rpc scada vulnerability zdi
Last synced: 10 Apr 2025
https://github.com/thezdi/poc
Proofs-of-concept
advantech cve-2016-0856 exploit poc proof-of-concept research rpc scada vulnerability zdi
Last synced: 02 Apr 2025
https://github.com/StarCrossPortal/scalpel
scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。
cve exploits fuzzing poc scanner vulnerabilities vulnerability
Last synced: 11 Jul 2025
https://github.com/bigblackhat/oFx
漏洞批量验证框架
cve exploit poc scanner verify-framework vulnerability vulnerability-scanners
Last synced: 12 Jul 2025
https://github.com/vulscanteam/vulscan
vulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...
exploit-databa exploitation-framework poc pocscan pocscanner scanner-web security-tools sesecurity-vulnerability vulnerability vulnerability-database-entry vulnerability-databases vulnerability-scanners vulnerability-scanning vulscan webscan webscanner
Last synced: 02 Apr 2025
https://github.com/yqcs/prismx
:: Prism X · Automated Enterprise Network Security Risk Detection and Vulnerability Scanning Tool / 棱镜 X · 自动化企业网络安全风险检测、漏洞扫描工具
appscan awvs exp fscan goby nessus nuclei poc prismx vulnerability webscanner
Last synced: 09 Apr 2025
https://github.com/dreadlocked/drupalgeddon2
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
cve-2018-7600 drupal drupal7 drupal8 drupalgeddon drupalgeddon2 exploit poc sa-core-2018-002
Last synced: 04 Apr 2025
https://github.com/jamf/CVE-2020-0796-RCE-POC
CVE-2020-0796 Remote Code Execution POC
cve-2020-0796 poc rce remote-code-execution smbghost
Last synced: 07 Sep 2025
https://github.com/lockgit/hacking
Hacker, ready for more of our story ! 🚀
attack attacker attacks cracker geek hack hacker hacking hacking-tool poc scanner security security-research security-vulnerability tool tools vulnerabilities vulnerability vulnerability-scanners
Last synced: 13 Apr 2025
https://github.com/LockGit/Hacking
Hacker, ready for more of our story ! 🚀
attack attacker attacks cracker geek hack hacker hacking hacking-tool poc scanner security security-research security-vulnerability tool tools vulnerabilities vulnerability vulnerability-scanners
Last synced: 13 Mar 2025
https://github.com/komomon/Komo
🚀Komo, a comprehensive asset collection and vulnerability scanning tool. Komo 一个综合资产收集和漏洞扫描工具,集成了20余款工具,通过多种方式对子域进行获取,收集域名邮箱,进行存活探测,域名指纹识别,域名反查ip,ip端口扫描,web服务链接爬取并发送给xray,对web服务进行POC漏洞扫描,对主机进行主机漏洞扫描。
amass bugbounty crawlergo ctfr emailall gospider hacking httpx information-gathering infosec ksubdomain naabu nuclei oneforall osint pentesting poc rad subfinder xray
Last synced: 12 Jul 2025
https://github.com/chushuai/wscan
Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.
cel-go chromedp crawler headless martian passive-vulnerability-scanner poc sql-injection subdomains testwaf vulnerability-scanner waf webscan wscan xss
Last synced: 11 Jul 2025
https://github.com/xnbox/DeepfakeHTTP
DeepfakeHTTP is a web server that uses HTTP dumps as a source for responses.
api demo dummy dump graphql http http-server mock mocks-server poc qa qa-automation rest rest-api restful-api spies stub test-automation testing testing-tools
Last synced: 02 Apr 2025
https://github.com/joaomatosf/javadeserh2hc
Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).
deserialization java javadeser jboss jvm lab poc reverse-shell vulnerability
Last synced: 13 May 2025
https://github.com/joaomatosf/JavaDeserH2HC
Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).
deserialization java javadeser jboss jvm lab poc reverse-shell vulnerability
Last synced: 12 Mar 2025
https://github.com/ojasookert/CVE-2017-0785
Blueborne CVE-2017-0785 Android information leak vulnerability
blueborne cve-2017-0785 exploit poc
Last synced: 11 Jul 2025
https://github.com/1n3/wordpress-xmlrpc-brute-force-exploit
Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield
0day exploit poc wordpress wordpress-xmlrpc xml-rpc
Last synced: 04 Apr 2025
https://github.com/1N3/Wordpress-XMLRPC-Brute-Force-Exploit
Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield
0day exploit poc wordpress wordpress-xmlrpc xml-rpc
Last synced: 09 Jul 2025
https://github.com/dongfangyuxiao/BurpExtend
基于Burp插件开发打造渗透测试自动化
burpsuite-extender passive-vulnerability-scanner poc security security-tools sqlinjection vulnerability-scanner xss
Last synced: 11 Jul 2025
https://github.com/xsscx/commodity-injection-signatures
Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT
burp burpsuite exploit fuzzing header html http injection injection-signatures input javascript malicious poc random rce xss
Last synced: 05 Apr 2025
https://github.com/xsscx/Commodity-Injection-Signatures
Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT
burp burpsuite exploit fuzzing header html http injection injection-signatures input javascript malicious poc random rce xss
Last synced: 11 Jul 2025
https://github.com/bytecode77/self-morphing-csharp-binary
Executable that mutates its own code
Last synced: 08 Apr 2025
https://github.com/orleven/Tentacle
Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.
exploit-framework fofa poc poc-script poc-vulnerability-verification shodan tentacle
Last synced: 11 Jul 2025
https://github.com/orleven/tentacle
Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.
exploit-framework fofa poc poc-script poc-vulnerability-verification shodan tentacle
Last synced: 05 Apr 2025
https://github.com/unclecheng-li/poc-lab
Recent CVE PoC & reproduction scripts. Focused on high-severity vulnerabilities across Linux kernel, Windows, macOS and more.
c cybersecurity linux poc python python3 vulnerability
Last synced: 27 May 2026
https://github.com/jiangsir404/POC-S
POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC
cnvd-2020-10487 dnslog pentest-scripts poc poc-t pocs pocsuite tomcat-ajp-lfi
Last synced: 11 Jul 2025
https://github.com/hktalent/spring-spel-0day-poc
spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963
0day cve-2022-22963 exp java poc rce spel spring spring-cloud-function
Last synced: 06 Apr 2025
https://github.com/a2u/cve-2018-7600
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
cve-2018-7600 drupal drupalgeddon2 exploit poc sa-core-2018-002
Last synced: 06 Apr 2025
https://github.com/bytecode77/living-off-the-land
Fileless attack with persistence
Last synced: 16 May 2025
https://github.com/TeraSecTeam/ary
Ary 是一个集成类工具,主要用于调用各种安全工具,从而形成便捷的一键式渗透。
automation penetration-testing pentest poc sqlinjection vulnerability vulnerability-scanners xss
Last synced: 11 Jul 2025
https://github.com/Yong-An-Dang/nuclei-plus
Functional enhancement based on nuclei. 基于 nuclei 的功能增强。
ai allinone editor nuclei nuclei-plus plugin-system poc template
Last synced: 07 Sep 2025
https://github.com/adamyordan/cve-2019-1003000-jenkins-rce-poc
Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
cve cve-2019-1003000 exploit groovy information-security jenkins poc rce security security-1266
Last synced: 13 Oct 2025
https://github.com/guillaumefalourd/poc-github-actions
Various proofs of concept examples using Github Actions 🤖
beginners examples github-actions poc proof-of-concept workflows
Last synced: 16 May 2025