An open API service indexing awesome lists of open source software.

Exploit

Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.

https://github.com/krishpranav/exploit-framework

A multiple reverse shell sessions/clients manager via terminal written in go

ctf exploit exploit-framework exploitation go golang reverse-shell reverse-shell-as-a-service

Last synced: 15 Apr 2025

https://github.com/0x00-0x00/-cve-2017-9805

Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)

apache cve exploit struts

Last synced: 22 Nov 2024

https://github.com/b4keSn4ke/Invoke-WinSATBypass

Powershell UAC Bypass script leveraging WinSAT.exe

exploit exploitation exploits powershell uac uac-bypass uacbypass windows windows-10

Last synced: 04 Dec 2024

https://github.com/cxm95/ida_wrapper

An IDA_Wrapper for linux, shipped with an Function Identifier. It works well with Driller on static linked binaries.

aeg angr driller exploit flair ida static-analysis

Last synced: 10 May 2025

https://github.com/voidsec/cve-2020-1337

CVE-2020-1337 a bypass of (PrintDemon) CVE-2020-1048’s patch

0day cve-2020-1048 cve-2020-1337 exploit faxhell poc printdemon voidsec windows

Last synced: 09 Apr 2025

https://github.com/noraj/Bludit-auth-BF-bypass

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass

authentication bludit bruteforce bypass cms cve-2019-17240 exploit poc proof-of-concept

Last synced: 21 Nov 2024

https://github.com/noraj/bludit-auth-bf-bypass

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass

authentication bludit bruteforce bypass cms cve-2019-17240 exploit poc proof-of-concept

Last synced: 12 Apr 2025

https://github.com/i32-sudo/vulnerablepatchguardexploit

A Vulnerable PatchGuard Exploit that can be used to disable PatchGuard on Runtime.

battleye be bypass exploit latest patchguard pg undetected working

Last synced: 15 Jan 2025

https://github.com/hktalent/weblogic_java_des

weblogic T3 collections java InvokerTransformer Transformer InvokerTransformer weblogic.jndi.WLInitialContextFactory

collections deserialization exploit hacker hacking-tool invokertransformer java rce remote-control remote-execution tools transformer weblogic

Last synced: 19 Nov 2024

https://github.com/depau/fastgate-python

Python tools for Fastweb FastGATE exploits

exploit pwn python router

Last synced: 12 Apr 2025

https://github.com/voidsec/cve-2019-5624

A proof of concept for Metasploit's CVE-2019-5624 vulnerability (Rubyzip insecure ZIP handling RCE)

cve-2019-5624 exploit metasploit metasploit-framework poc rce rubyzip

Last synced: 17 Mar 2025

https://github.com/qeeqbox/falcon

Collection of exploits that were verified by an automated system

cve exploit patch python

Last synced: 13 Apr 2025

https://github.com/padsalatushal/cve-2011-2523

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

cve cve-2011-2523 exploit python security vsftpd-exploit

Last synced: 11 Apr 2025

https://github.com/makindotcc/cs2-server-crasher-vac-live-v2

cs2 server crasher found by me. already patched on valve ds. posted for educational purposes as tutorial how to beat cheaters

crasher cs2 exploit vac

Last synced: 23 Apr 2025

https://github.com/theori-io/web3-publications

Collection of Web3 Audits and Publications by ChainLight of Theori

blockchain ethereum exploit fuzzing publications security smart-contract web3

Last synced: 08 May 2025

https://github.com/shelld3v/python-shell-cheat-sheet

Full python reverse shell and bind shell payloads

bind-shell cheat-sheet exploit hacking python python3 reverse-shell security shell

Last synced: 18 Feb 2025

https://github.com/demining/twist-attack

In this article, we will implement a Twist Attack with an example and show how, using certain points on the secp256k1 elliptic curve, we can get partial private key values ​​and restore a Bitcoin Wallet within 5-15 minutes using “Sagemath pollard rho function: (discrete_log_rho)” and “ Chinese Remainder Theorem” .

attack attacker bitcoin bitcoin-wallet blockchain blockchain-technology cryptocurrency exploit exploiting exploiting-vulnerabilities hack hacking vulnerabilities vulnerability vulnerability-scanners

Last synced: 11 Jan 2025

https://github.com/zeyad-azima/cve-2022-1388

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

cve cve-2022-1388 exploit f5 f5-bigip icontrol rest-api

Last synced: 07 May 2025

https://github.com/p0dalirius/cve-2018-16763-fuelcms-1.4.1-rce

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

cms cve-2018-16763 exploit fuelcms

Last synced: 30 Dec 2024

https://github.com/0xbitx/dedsec_bkif

DEDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS.

bluetooth bluetooth-keystroke exploit keystroke keystroke-injection

Last synced: 04 Mar 2025

https://github.com/p0dalirius/cve-2022-26159-ametys-autocompletion-xml

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

ametys autocompletion cms exploit plugin

Last synced: 30 Dec 2024

https://github.com/gnebbia/shellcoder

Create shellcode from executable or assembly code

exploit exploitation perl shellcode

Last synced: 09 Apr 2025

https://github.com/xsscx/ios-arm-research

UPDATED: All the action is at https://github.com/xsscx/srd

development discovery exploit fuzzing vulnerability

Last synced: 26 Apr 2025

https://github.com/x86-512/vxpp

VFGadget locator to facilitate Counterfeit Object-Oriented Programming (COOP) and Loop-Oriented Programming (LOP) attacks to bypass advanced security protections like Intel CET and Control-Flow Guard (CFG) to achieve Remote Code Execution.

binary-exploitation buffer-overflow cet cfg code-reuse control-flow-guard control-flow-integrity coop exploit exploit-development intel-cet lop rce rce-exploit rop rop-gadgets ropgadget security-bypass uaf use-after-free

Last synced: 29 Apr 2025

https://github.com/josephgreens/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

authentication bloxfruit-script bloxfruits-autofarm-script executer exploit game gui hack lua nexus-roblox roblox roblox-lua roblox-script roblox-scriptbloxfruits-autofarm-script roblox-scripts roblox-synapse robloxscripts script-hub supported whitelist

Last synced: 06 Dec 2024

https://github.com/m3ssap0/springbreakvulnerableapp

WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!

cve-2017-8046 exploit security security-tools spring-break spring-data-rest vulnerability vulnerability-scanners

Last synced: 04 May 2025

https://github.com/byt3n33dl3/thc-cartel

Configurations and Deprecated payloads. Some useful scripts for Cobaltstrike.

exploit kali-linux metasploit operating-system payloads pentesting shellcode

Last synced: 29 Mar 2025

https://github.com/byt3n33dl3/crawler_v2

Remote access Trojan based (Client) After the Malware hits the Kernel.

compiler crawler exploit offensive-security pentesting rat

Last synced: 13 Apr 2025

https://github.com/nyawox/nixtendo-switch

NixOS module with some useful features for hacked nintendo switch

cve-2018-6242 exploit hekate nintendo-switch nix-flake nixos nixos-module usb

Last synced: 13 Apr 2025

https://github.com/Supersonic/Wallbreak

Exploit app for CVE-2021-39670 and CVE-2021-39690, two permanent denial-of-service vulnerabilities in Android's wallpaper system

android cve exploit security vrp

Last synced: 10 Mar 2025

https://github.com/AmoloHT/CVE-2022-26134

「💥」CVE-2022-26134 - Confluence Pre-Auth RCE

confluence cve cve-2022-26134 exploit hacking infosec rce security

Last synced: 10 Mar 2025

https://github.com/byt3n33dl3/crypealbatros

CrypeAlbatros is a handy Offensive tool to Scan Microsoft Windows over the Samba protocol.

exploit mapping microsoft post-exploitation relay samba smb windows

Last synced: 16 Apr 2025

https://github.com/entr0pie/cve-2023-27163

Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1)

cybersecurity exploit go golang poc python3 request-baskets server-side-request-forgery ssrf

Last synced: 27 Apr 2025

https://github.com/kkent030315/libinject

A dll injector static library for Win x64 processes with handle elevation supported

dll exploit injector kernel-exploit kernel-exploits privilege-elevation privilege-escalation

Last synced: 13 Feb 2025

https://github.com/demining/twist-attack-2

In this article, we will implement a Twist Attack with an example and show how, using certain points on the secp256k1 elliptic curve, we can get partial private key values ​​and restore a Bitcoin Wallet within 5-15 minutes using “Sagemath pollard rho function: (discrete_log_rho)” and “ Chinese Remainder Theorem” .

attack attacker bitcoin bitcoin-wallet blockchain blockchain-technology cryptocurrency exploit exploiting exploiting-vulnerabilities hack hacking vulnerabilities vulnerability vulnerability-scanners

Last synced: 01 Mar 2025

https://github.com/m4drat/CVE-2013-2028-Exploit

CVE-2013-2028 python exploit

cve exploit nginx pwn

Last synced: 10 Mar 2025

https://github.com/scipag/proxyexe

Launch a Windows EXE file with this EXE file (application filter evasion)

bypass bypass-antivirus bypass-av bypassantivirus bypassing bypassing-avs evasion executable exploit exploitation filter filter-files proxy

Last synced: 23 Feb 2025

https://github.com/noraj/atmail-exploit-toolchain

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)

atmail csrf exploit plugin rce reverse-shell xss

Last synced: 12 Apr 2025

https://github.com/coretool/botmap

A nmap & MSF bot

bot exploit metasploit pentest vuln

Last synced: 25 Mar 2025

https://github.com/eqstlab/cve-2024-8353

GiveWP PHP Object Injection exploit

cve exploit php poc proof-of-concept security vulnerability

Last synced: 11 Apr 2025

https://github.com/voidsec/slae

SecurityTube Linux Assembly Expert x86 Exam

exploit exploitation metasploit pentester shellcode slae voidsec

Last synced: 09 Apr 2025

https://github.com/fedebuonco/yapppwn

YAPPPWN is a Rust rewrite of the PPPWN Exploit by TheOfficialFloW.

exploit explotation homebrew jailbreak playstation pnet pppwn ps4 ps4-jailbreak ps4exploit rust

Last synced: 11 Feb 2025

https://github.com/alexandre-bartel/cve-2019-12594

This is a PoC for CVE-2019-12594, a vulnerability in DOSBox 0.74-2.

cve dos dosbox exploit poc proof-of-concept vulnerability

Last synced: 01 Dec 2024

https://github.com/elastic/camera-hacks

PoC exploits and tools for conducting vulnerability research against AJCloud Wi-Fi security camera products

ajcloud camera exploit hacking iot security wansview

Last synced: 04 Feb 2025

https://github.com/efchatz/bl0ck

Bl0ck: a tool to interrupt the transmission of QoS Data frames in Wi-Fi 5 and 6 networks

80211 cve dos exploit wifi wpa2 wpa3

Last synced: 27 Mar 2025

https://github.com/kitikod6/roblox-bunni-executor

Bunni is a premier Roblox exploiting platform, renowned for its cutting-edge tools, rapid updates, and robust support. Developed by experienced professionals, it ensures maximum efficiency, security, and a seamless user experience with features like HWID spoofer and extensive script support.

cheats code developer executor exploit free gaming github hacking injector lua modding open-source programming project roblox-bunni-executor script software tools

Last synced: 06 Dec 2024

https://github.com/x0reaxeax/exec-prot-bypass

Bypassing Linux Executable Space Protection using 20+ years old tools (CVE-2022-25265).

cve-2022-25265 dep-bypass exploit linux noexec

Last synced: 25 Apr 2025

https://github.com/jdgregson/disclosures

My publically disclosed vulnerability reports.

exploit exploits poc vulnerabilities vulnerability

Last synced: 19 Dec 2024

https://github.com/darkcodersc/freepbx-shell-admin-module

FreePBX PHP Web Shell Admin Module

exploit freepbx oscp php

Last synced: 12 Feb 2025

https://github.com/mawg0ud/invismalware

A Malware Evasion Technique, shellcode generation, syntax modification, anti-dynamic analysis & PE header modification.

antivirus cybersecurity dynamic-analysis exploit infosec malware payload research security shellcode static-analysis threat

Last synced: 01 Feb 2025

https://github.com/k8gege/dotnetnukeexploit

MSF moudle DotNetNuke GetShell & execute exploit

0day dotnetnuke exp exploit getshell metasploit msf poc rce

Last synced: 03 May 2025

https://github.com/chocapikk/cve-2023-5360

Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.

cve-2023-5360 exploit hacking infosec open-source penetration-testing python remote-code-execution royal-elementor-addons vulnerability web-security wordpress

Last synced: 13 Apr 2025

https://github.com/enty8080/tfp0

tfp0 (task for pid 0) is a kernel task port that grants full control over the iOS device's kernel. Access to this port is necessary for developing many types of exploits, including jailbreaks.

cve exploit ios iphone jailbreak macos payload tfp0 vulnerability

Last synced: 26 Jan 2025

https://github.com/rxzyx/wordle-answer-hack

Get the answer in both wordle and wordleunlimited.org

cheat exploit game hack javascript wordle wordle-game wordle-solver

Last synced: 01 Apr 2025

https://github.com/xorond/l0l

An exploit development kit with shellcodes and backdoors for various operating systems

backdoor exploit pwn shellcode

Last synced: 12 May 2025

https://github.com/mrtaheramine/cve-2018-10583

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by "xlink:href=file://192.168.0.2/test.jpg" within an "office:document-content" element in a ".odt XML document".

cve-2018-10583 exploit exploit-db exploit-development py

Last synced: 09 Apr 2025

https://github.com/voidsec/joomla_cve-2015-8562

A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)

cve-2015-8562 exploit joomla php rce vulnerability

Last synced: 09 Apr 2025

https://github.com/eschan145/dieknow

Bypass of DyKnow, the monitoring software used on school devices to monitor the hell out of them. Use responsibly.

bypass cpp cpu ctypes dll dyknow easy-to-use exploit gui hack performance-optimization proprietary python school school-app unblock win32 windows windows-api

Last synced: 17 Jan 2025

https://github.com/mfazrinizar/sqlzr-i

This is a Perl program to do an automated SQL Injection for pentesting web's SQL database protection. Coded by M.Fazri Nizar.

database exploit exploitation pentesting perl sql sql-i

Last synced: 08 May 2025

https://github.com/jamesjara/toolkit-exploit-hacking-seismologic-networks

toolkit for exploiting your own seismological networks

exploit netdb seismology

Last synced: 06 Apr 2025

https://github.com/lyzev/schummelpartie

Power up your Pummel Party experience with this customizable mod, built for friendly competition or solo practice.

bot cheat exploit hack lyzev melonloader mod mods partie party pummel pummelparty schummel schummelpartie

Last synced: 24 Feb 2025

https://github.com/esonhugh/chatgpt-web-setting-funny-abuse

Play with ChatGPT-Web and found the HTML rendering in description settings. [Add Custom js and html in the XSS payload to enhanced ChatGPT-Web]

chatgpt chatgpt-web demo exploit extension funny

Last synced: 22 Nov 2024

https://github.com/hupe1980/gomsf

Golang based RPC client to communicate with Metasploit

exploit golang metasploit meterpreter msf redteam rpc shell

Last synced: 16 Apr 2025

https://github.com/thewhiteh4t/cve-2019-11447

CutePHP Cute News 2.1.2 RCE PoC

cutenews cutephp cve-2019-11447 exploit python rce

Last synced: 12 Apr 2025

https://github.com/darkcodersc/yase-encoder

Yet Another Sub Encoder (YASE)

assembly exploit python sub-encoder

Last synced: 12 Feb 2025

https://github.com/codedsprit/cve-2022-22965

🤯 Exploit for SpringShell.

cve exploit springshell

Last synced: 27 Apr 2025

https://github.com/martinclauss/exim-rce-cve-2018-6789

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

binary-exploitation cve docker educational exim exim-exploit exploit exploit-development gdb learning-by-doing pwndbg pwntools rce vagrant

Last synced: 16 Dec 2024

https://github.com/hunthubspace/cve-2024-0757-exploit

A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)

bugbounty cve ethical-hacking exploit penetration-testing web

Last synced: 13 Apr 2025

https://github.com/enty8080/macdirtycow

Example of CVE-2022-46689 aka MacDirtyCow.

cve cve-2022-46689 exploit jailbreak macdirtycow macos

Last synced: 14 Apr 2025

https://github.com/aqhmal/pulsexploit

Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.

exploit information-extraction infosec offset pentest-script python3

Last synced: 10 May 2025

https://github.com/mawg0ud/cveforge

A tool to track & analyze Common Vulnerabilities and Exposures (CVEs).

automation cve cybersecurity detection exploit infosec malware pentesting python risk security vulnerability

Last synced: 05 Mar 2025

https://github.com/so1icitx/cve-2024-25600

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

bricks-builder bricksbuilder cve-2024-25600 exploit hacking pentesting python-3 python3 rce rce-exploit remote-code-execution security-research security-researcher vulnerability wordpress wordpress-plugin

Last synced: 08 Apr 2025

https://github.com/Esonhugh/ChatGPT-Web-Setting-Funny-Abuse

Play with ChatGPT-Web and found the HTML rendering in description settings. [Add Custom js and html in the XSS payload to enhanced ChatGPT-Web]

chatgpt chatgpt-web demo exploit extension funny

Last synced: 04 Apr 2025

https://github.com/sjord/protravel

Recursively exploit path traversal vulnerability

exploit python3

Last synced: 08 May 2025

https://github.com/mrcl0wnlab/nuclei-template-exploit-f5-big-ip-icontrol-rest-auth-bypass-rce-command-parameter

CVE-2022-1388 is an authentication bypass vulnerability in the REST component of BIG-IP’s iControl API that was assigned a CVSSv3 score of 9.8. The iControl REST API is used for the management and configuration of BIG-IP devices. CVE-2022-1388 could be exploited by an unauthenticated attacker with network access to the management port or self IP addresses of devices that use BIG-IP. Exploitation would allow the attacker to execute arbitrary system commands, create and delete files and disable services.

bigip bigip-rest-api cve-2022-1388 exploit f5-bigip nuclei nuclei-templates

Last synced: 27 Mar 2025

https://github.com/elijahhx/dead1ock-h4ck

"Dead1ock-h4ck" is an open-source project dedicated to exploring cybersecurity and ethical hacking techniques. The project aims to provide resources and tools for learning about network security, cryptography, and penetration testing.

cyber-defense cybersecurity cybersecurity-research dead1ock-h4ck exploit github hacking hacktivism infosec malware pentesting programming ransomware security technology vulnerability

Last synced: 23 Apr 2025

https://github.com/noraj/fuelcms-rce

Fuel CMS 1.4 - Remote Code Execution

cve-2018-16763 exploit fuel-cms poc rce remote-code-execution

Last synced: 12 Apr 2025

https://github.com/xsscx/ios-arm-binaries

UPDATED: All the action is at https://github.com/xsscx/srd

arm development discovery exploit ios vulnerability

Last synced: 26 Feb 2025