Exploit
Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.
- GitHub: https://github.com/topics/exploit
- Wikipedia: https://en.wikipedia.org/wiki/Exploit_(computer_security)
- Created by: The cybersecurity community
- Related Topics: hacking, cybersecurity, penetration-testing, vulnerability-assessment,
- Aliases: exploits, vulnerability-exploit,
- Last updated: 2026-06-19 00:11:12 UTC
- JSON Representation
https://github.com/jamesjara/toolkit-exploit-hacking-seismologic-networks
toolkit for exploiting your own seismological networks
Last synced: 06 Apr 2025
https://github.com/hupe1980/gomsf
Golang based RPC client to communicate with Metasploit
exploit golang metasploit meterpreter msf redteam rpc shell
Last synced: 16 Apr 2025
https://github.com/noraj/openemr-rce
OpenEMR <= 5.0.1 - (Authenticated) Remote Code Execution
cve-2018-15142 exploit openemr openemr-exploit openemr-rce openemr-shell-upload openemr-vulnerability poc proof-of-concept rce remote-code-execution
Last synced: 12 Apr 2025
https://github.com/thewhiteh4t/cve-2019-11447
CutePHP Cute News 2.1.2 RCE PoC
cutenews cutephp cve-2019-11447 exploit python rce
Last synced: 04 Jul 2025
https://github.com/gemesa/shadow-shell
Cyber lab designed for analyzing shellcode and supporting malware analysis
aarch64 amd64 arm64 assembly exploit frida frida-scripts malware-analysis malware-research reverse-engineering rust shellcode shellcode-development stack-smashing x64 x86-64
Last synced: 29 Oct 2025
https://github.com/hunthubspace/cve-2024-0757-exploit
A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)
bugbounty cve ethical-hacking exploit penetration-testing web
Last synced: 13 Apr 2025
https://github.com/mishakorzik/exploitaddr
Find website ips addresses and website ip behind cloudflare.
address api censys censys-search cloudflare domain exploit hacking hacking-tool hacking-tools ip ip-address ipv4 ipv6 linux linux-hacking python python3 termux termux-hacking
Last synced: 16 May 2025
https://github.com/cryxnet/cve-2022-42889-rce
Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability)
cve-2022-42889 exploit exploits poc security vulnerability
Last synced: 27 Dec 2025
https://github.com/unicordev/exploit-cve-2020-5844
Exploit for CVE-2020-5844 (Pandora FMS v7.0NG.742) - Remote Code Execution
cve cve-2020-5844 exploit hackthebox linux pandora penetration-testing proof-of-concept python remote-code-execution unicord vulnerability
Last synced: 10 Jun 2025
https://github.com/mordavid/cve-2023-38831-winrar-exploit-generator-poc
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
archive cve-2023-38831 exploit rce rce-exploit remote-code-execution winrar
Last synced: 12 Jun 2025
https://github.com/martinclauss/exim-rce-cve-2018-6789
This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.
binary-exploitation cve docker educational exim exim-exploit exploit exploit-development gdb learning-by-doing pwndbg pwntools rce vagrant
Last synced: 27 Aug 2025
https://github.com/mfazrinizar/sqlzr-i
This is a Perl program to do an automated SQL Injection for pentesting web's SQL database protection. Coded by M.Fazri Nizar.
database exploit exploitation pentesting perl sql sql-i
Last synced: 08 May 2025
https://github.com/so1icitx/cve-2024-25600
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
bricks-builder bricksbuilder cve-2024-25600 exploit hacking pentesting python-3 python3 rce rce-exploit remote-code-execution security-research security-researcher vulnerability wordpress wordpress-plugin
Last synced: 08 Apr 2025
https://github.com/r3li4nt/ctf-retos
Retos de Captura la bandera (CTF) resueltos en español.
ctf easy escalate-privilages exploit hacking hard kali linux medium pentesting redteam root-me security vulnerability vulnhub wifi
Last synced: 31 Jul 2025
https://github.com/abdullah2993/zong-wifi
exploit hack unlock unlocker vulnerability zong
Last synced: 20 Jun 2025
https://github.com/xewdy444/netgrave
A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)
camera exploit netwave security vulnerability
Last synced: 11 Mar 2026
https://github.com/sjord/protravel
Recursively exploit path traversal vulnerability
Last synced: 08 May 2025
https://github.com/elmerikh/beryl
Payload Dropper with Persistance & Privesc & UAC bypass 🐱👤
avbypass backdoor backdoor-attacks backdoor-dropper cybersecurity cybersecurity-education dropper exploit hacking-tool payload-generator payload-injector python redteaming redteamtool shellcode-injector shellcode-loader uac-bypass windows windowsdefenderbypass
Last synced: 28 Apr 2025
https://github.com/noraj/fuelcms-rce
Fuel CMS 1.4 - Remote Code Execution
cve-2018-16763 exploit fuel-cms poc rce remote-code-execution
Last synced: 12 Apr 2025
https://github.com/xsscx/ios-arm-binaries
UPDATED: All the action is at https://github.com/xsscx/srd
arm development discovery exploit ios vulnerability
Last synced: 04 Mar 2026
https://github.com/ibnusyawall/mytools
commandline-interface exploit nodejs npm tools-engineering vulnerability
Last synced: 22 Jul 2025
https://github.com/0x00-0x00/cve-2016-10033
PHPMailer < 5.2.18 Remote Code Execution Exploit
2016-10033 cve exploit php phpmailer
Last synced: 12 Jul 2025
https://github.com/paulveillard/cybersecurity-exploits
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Software Exploits in Cybersecurity.
Last synced: 07 Jan 2026
https://github.com/elijahhx/dead1ock-h4ck
"Dead1ock-h4ck" is an open-source project dedicated to exploring cybersecurity and ethical hacking techniques. The project aims to provide resources and tools for learning about network security, cryptography, and penetration testing.
cyber-defense cybersecurity cybersecurity-research dead1ock-h4ck exploit github hacking hacktivism infosec malware pentesting programming ransomware security technology vulnerability
Last synced: 23 Apr 2025
https://github.com/voidsec/tivoli-madness
Advisory for CVE-2020-28054 & stack based buffer overflow in IBM Tivoli Storage Manager
authorization-bypass buffer-overflow exploit ibm jamodat tivoli voidsec
Last synced: 09 Apr 2025
https://github.com/systemvll/windows-extension-exploit
Exploit for Windows extension, it can hide the .exe extension and replace it with any other extension
0day exploit windows windows-exploit
Last synced: 21 Jun 2025
https://github.com/francescodisalesgithub/simpleviruswriting
An example of basic virus writing in C
c exploit fallocate fork-bomb hacking hide-messages kernel linux passwords shadowfile timebomb virus-writing
Last synced: 25 Jun 2025
https://github.com/d3ext/reflex-gallery-exploit
Reflex Gallery 3.1.3 Arbitrary File Upload to RCE Exploit
2022 awesome ctf exploit hacking hackthebox htb kali kali-linux mrrobot oscp owasp pentesting reflex-gallery vuln wordpress
Last synced: 07 May 2025
https://github.com/lucabarile/toctou
Exploiting TOCTOU vulnerability using OpLock and Junctions
cve elevation-of-privilege eop exploit junction local-privilege-escalation lpe oplock opportunistic-lock poc pop-a-shell proof-of-concept race-conditions symbolic-link symlink toctou vulnerability
Last synced: 15 Apr 2025
https://github.com/emmaconnor/moria
Python library for interacting with in-memory C structures using data mined from binary DWARF debug info.
binary-exploitation c exploit exploit-development exploitation exploits offensive-security python security
Last synced: 11 Mar 2026
https://github.com/nerdsinspace/nocom-frontend
The No Comment web application frontend.
angular exploit javascript minecraft
Last synced: 13 Apr 2025
https://github.com/joe12387/safari-canvas-fingerprinting-exploit
An exploit for Safari 17.4 and lower that enables fingerprinting Safari users using OffscreenCanvas and SharedWorkers even if fingerprinting protections are enabled.
apple browser browser-fingerprint browser-fingerprinting exploit fingerprint fingerprinting ios javascript macos safari vulnerabilities vulnerability
Last synced: 16 Mar 2026
https://github.com/mrcl0wnlab/nuclei-template-exploit-f5-big-ip-icontrol-rest-auth-bypass-rce-command-parameter
CVE-2022-1388 is an authentication bypass vulnerability in the REST component of BIG-IP’s iControl API that was assigned a CVSSv3 score of 9.8. The iControl REST API is used for the management and configuration of BIG-IP devices. CVE-2022-1388 could be exploited by an unauthenticated attacker with network access to the management port or self IP addresses of devices that use BIG-IP. Exploitation would allow the attacker to execute arbitrary system commands, create and delete files and disable services.
bigip bigip-rest-api cve-2022-1388 exploit f5-bigip nuclei nuclei-templates
Last synced: 24 Feb 2026
https://github.com/kardespro/nosqlmap
NoSQLMap CLI Tool is a command-line interface (CLI) tool designed to test for NoSQL injection vulnerabilities using Node.js, TypeScript, and Axios. It supports both HTTP and HTTPS requests and works with all HTTP methods.
exploit mongodb mongodb-database mongoose nosqlmap pentesting scan-tool security security-tools sqlmap
Last synced: 24 Oct 2025
https://github.com/team0se7en/cve-2020-8816
Pi-hole ( <= 4.3.2) authenticated remote code execution.
cve-2020-8811 exploit golang pi-hole privesc rce
Last synced: 15 Jun 2025
https://github.com/0xapt/evil-xmlrpc
evil-xmlrpc is a tool that I created to help me bruteforce Wordpress user accounts using xmlrpc.php while bypassing iThemes Security preventing lockouts
exploit ithemes-security python wordpress
Last synced: 07 Sep 2025
https://github.com/synap5e/razor-eop-xiao
Razor installer elevation of privilege trigger + automation with Seeeduino XIAO
circuitpython eop exploit micropython privesc razor
Last synced: 15 Apr 2025
https://github.com/crllect/zorro
Frontend-only game and unblock website with a pretty big lib. Only a fun side-project, dont expect daily updates
Last synced: 23 Jun 2025
https://github.com/vulnsphere/ai_infra_vuln_pocs
This is the PoC repository of LLM service. Updating...
exploit llm ml nuclei nuclei-templates poc security vulnerability
Last synced: 27 Jan 2026
https://github.com/siddhant385/flask-phishing
PHISHING FRAMEWORK BUILT OVER FLASK AND COULD BE DEPLOYED OVER WEB TO SHOW THE RISKS OF PHISHING OVER THE WEB WITH PASSWORD FETCH OVER TELEGRAM
brute-force exploit flask flask-login flask-phishing flask-web instagram iplogger ngrok phishing phishing-attacks phishing-kit phishing-page phishing-script phishing-tool portforward web zphisher
Last synced: 14 Apr 2025
https://github.com/aw-junaid/security-and-hacking
Explore ethical hacking and security: penetration testing, vulnerability scanning, and exploit development. Includes tools, scripts, and hands-on labs.
ethical-hacking exploit hacking penetration-testing security vulnerabilities vulnerability-scanners
Last synced: 08 Jan 2026
https://github.com/iosdec/sandbox-escape-poc-ios-13.4.1-and-lower
This is a POC of a sandbox escape by found by Siguza. Works up to iOS 13.4.1.
exploit ios objective-c sandbox-escape
Last synced: 14 Apr 2025
https://github.com/flutterguard/flutterguard-cli
Know and see everything an attacker can extract and get from your published Flutter app
android apk cli dart exploit flutter opensource reverse-engineering security static-analysis
Last synced: 13 Jan 2026
https://github.com/demining/cold-and-hot-wallets
Cold Wallets and Hot Wallets how to find vulnerabilities and eliminate various attacks on the Blockchain
attack attacker attacks bitcoin bitcoin-transaction bitcoin-wallet blockchain coldwallet coldwaters cryptocurrency exploit exploits hack hacking vulnerabilities vulnerability
Last synced: 13 May 2026
https://github.com/codercooke/osx-thumbnails
Reassemble thumbnails from osx quicklook thumbnail cache
exploit forensics mac macos osx quicklook thumbnails
Last synced: 07 Jul 2025
https://github.com/acceis/exploit-cve-2022-24780
iTop < 2.7.6 - (Authenticated) Remote command execution
cve cve-2022-24780 exploit rce ssti
Last synced: 16 Jul 2025
https://github.com/geniuszly/CVE-2022-46080
it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port, and password. It validates the inputs and logs the process, providing feedback on whether the exploit was successful.
buffer-overflow cve cve-2022-46080 cybersecurity ethical-hacking exploit exploit-development linux nexxt nexxt-router penetration-testing poc rce rce-exploit router security telnet vulnerability vulnerability-research
Last synced: 07 May 2025
https://github.com/lucabarile/cve-2023-23396
Exploit and report for CVE-2023-23396.
cve-2023-23396 denial-of-service disclosure excel-exploit exploit full-disclosure kb5002356 kb5002362 microsoft-excel office-365 paper poc proof-of-concept report vulnerability vulnerability-disclosure white-paper write-up writeup
Last synced: 25 Jan 2026
https://github.com/k3rnel-dev/winrarexploit
CVE-2023-38831-WINRAR-EXPLOIT GENERATOR
Last synced: 13 May 2025
https://github.com/typicalmodmaker/cve-2024-4956
Proof-Of-Concept (POC) for CVE-2024-4956
cve cve-2024-4956 exploit poc proof-of-concept proofofconcept vulnerability
Last synced: 10 Apr 2025
https://github.com/rxzyx/ps3d-ultimate-client
The best hacks for Pixel Strike 3D (PS3D) you can find.
3d aws exploit game hack mod pixel pixelstrike pixelstrike3d playfab ps3d python strike
Last synced: 30 Apr 2026
https://github.com/geniuszly/cve-2022-46080
it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port, and password. It validates the inputs and logs the process, providing feedback on whether the exploit was successful.
buffer-overflow cve cve-2022-46080 cybersecurity ethical-hacking exploit exploit-development linux nexxt nexxt-router penetration-testing poc rce rce-exploit router security telnet vulnerability vulnerability-research
Last synced: 11 Apr 2025
https://github.com/hupe1980/gopherfy
Tool to generate gopher links for exploiting SSRF
exploit fastcgi gopher http mysql postgresql smtp ssrf
Last synced: 06 Jul 2025
https://github.com/n132/dec-safe-linking
A general way to Recover Safe linking protected value/pointer
Last synced: 21 Jul 2025
https://github.com/lucabarile/dll-hijacking
DLL Hijacking using DLL Proxying technique
cve dll-hijacking dll-proxying elevation-of-privilege exploit exported-functions hijacking local-privilege-escalation mingw-w64 poc pop-a-shell privilege-escalation proof-of-concept vulnerability windows-privilege-escalation
Last synced: 30 Jan 2026
https://github.com/padsalatushal/cve-2018-16763
Fuel CMS 1.4.1 - Remote Code Execution
cve cve-2018-16763 exploit fuelcms python
Last synced: 22 Sep 2025
https://github.com/cokebeer/logi
Logi is a LDAP/MySQL server focusing on pingback deserialize recon and exploit.
commons-beanutils custom cve-2020-14644 deserialize exploit gadget go java jdbc jndi ldap log4j mysql probe server wordlist
Last synced: 09 Apr 2025
https://github.com/0xbitx/dedsec_malware_dropper
linux based super-stealthy Dropper, that can create a fully undetected linux malware executable.
custom-payload dropper exploit fud fud-backdoor linux-tool malware rat undetectable-malware
Last synced: 02 Dec 2025
https://github.com/bl4ck44/ctf-desafios
CTF Retos de Captura la bandera resueltos.
ctf ctf-challenges exploit hacking hackthebox hard kali kali-linux pentesting security vulnhub
Last synced: 31 Jul 2025
https://github.com/al1ex/cve-2020-35729
CVE-2020-35729
cve-2020-35729 exploit klogserver
Last synced: 11 Apr 2025
https://github.com/geniuszly/CVE-2022-45701
it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script automates the process of authorization, payload generation, and execution, allowing for remote command execution on the target device.
arris arris-modem arris-router buffer-overflow cve cve-2022-45701 cybersecurity ethical-hacking exploit exploit-development linux penetration-testing poc python security snmp vulnerability vulnerability-research
Last synced: 07 May 2025
https://github.com/doyensec/sshnuke_info
SSH Nuke Info
exploit exploit-development sshd vulnerability
Last synced: 26 Jun 2025
https://github.com/nerdsinspace/nocom-http
The No Comment web application backend.
api exploit java minecraft spring spring-boot
Last synced: 13 Apr 2025
https://github.com/geniuszly/cve-2022-44149
it is script designed to interact with a router by sending a payload to its system tools. The script retrieves the router's configuration from environment variables to ensure security. It includes functions for generating an authorization header, sending a payload, and logging the process.
cve cve-2022-44149 cybersecurity ethical-hacking exploit exploit-development linux payload penetration-testing poc privilege-escalation security vulnerability vulnerability-research
Last synced: 11 Apr 2025
https://github.com/geniuszly/cve-2022-45701
it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script automates the process of authorization, payload generation, and execution, allowing for remote command execution on the target device.
arris arris-modem arris-router buffer-overflow cve cve-2022-45701 cybersecurity ethical-hacking exploit exploit-development linux penetration-testing poc python security snmp vulnerability vulnerability-research
Last synced: 11 Apr 2025
https://github.com/zebbern/ctf-resources
🧾 | Cybersecurity and CTF Resource that i gathered over the years
anonymous blue-team cheatsheets cryptography ctf-tools cybersecurity evasion-techniques exploit hacking hash-credentials malware obfuscation osint penetration-testing pentesting red-team reverse-engineering reverse-shell steganography web-vulnerability
Last synced: 12 Mar 2026
https://github.com/geniuszly/gendecryptauthme
A Python tool for decrypting passwords hashed with the AuthMe SHA256 algorithm. Ideal for penetration testing and security audits on Minecraft servers using the AuthMe authentication plugin.
authentication-bypass authme authme-sha256 cybersecurity decryption ethical-hacking exploit gendecryptauthme minecraft password-decryption penetration-testing python reverse-engineering security-tools sha256 sha256-hash
Last synced: 15 Jun 2025
https://github.com/jcs090218/reverse_shell
Reverse shell implementation using Python
exploit microservice reverse-shell vulnerability
Last synced: 28 Feb 2026
https://github.com/devsebastian44/ctf-desafios
CTF Retos de Captura la bandera resueltos.
ctf ctf-challenges exploit hacking hackthebox hard kali kali-linux pentesting security vulnhub
Last synced: 09 Oct 2025
https://github.com/0xmachos/cve-2019-8561
Proof of concept exploit for CVE-2019-8561 discovered by @jbradley89
exploit macos poc proof-of-concept
Last synced: 14 Jul 2025
https://github.com/siddhant385/karavas
A remote acess tool without port forwarding. An Evil Os implementation for windows
byob evilosx evilwindows exploit flask fud fud-rat karavas payload payload-generator post-exploitation python3 rat remote-access-tool remote-access-trojan reverse-shell simple
Last synced: 14 Apr 2025
https://github.com/sgabe/cve-2019-1476
AppXSvc Arbitrary File Overwrite DoS
dos-attack exploit proof-of-concept vulnerability windows10
Last synced: 17 Oct 2025
https://github.com/slluxx/windows-reverse-shell
Reverse-shell payloads and scripts
2021 exploit hacking powershell reverse-shell script undetected windows working
Last synced: 15 Mar 2026
https://github.com/mustafadalga/dictionary-attack
Bir hedef web sitesi veya ip adresine giriş için sözlük saldırısı yapan bir script.
cyber-security cyber-threat-intelligence cybersecurity dictionary-attack exploit hackathon hacker hacking hacking-tool hacking-tools python python-3 python-script python3 python3-script web-hackathon web-hacking website-hacking
Last synced: 30 Apr 2025
https://github.com/z3n70/CVE-2021-43798
Simple program for exploit grafana
bugbounty cybersecurity exploit grafana pentesting
Last synced: 10 Mar 2025
https://github.com/0xnonames/croissanted.py
A Python script exploiting Discord's authorization token.
Last synced: 24 Jul 2025
https://github.com/teemsploit/situationadmin.lua
A console admin script built for synapseX & Script-Ware may not work on other executors.
admin exploit lua luau rlua roblox roblox-cheat roblox-hack roblox-script robloxlua script-ware synapsex teemsploit
Last synced: 04 Oct 2025
https://github.com/alexandre-bartel/cve-2018-20343
PoC for CVE-2018-20343
build-engine cve exploit vulnerability
Last synced: 25 Jul 2025
https://github.com/cybersecsi/blueborne-dockerized
Repo code for the related post on SecSI Blog: https://secsi.io/blog/blueborne-kill-chain-on-dockerized-android
android aslr aslr-bypass blueborne bluetooth container docker exploit secsi
Last synced: 13 Jul 2025
https://github.com/mauricelambert/cve-2021-31166
CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.
bluescreen crash cve cve-2021-31166 denial-of-service dos exploit iis metasploit microsoft nmap payload powershell python3 ruby vulnerability webserver
Last synced: 04 Sep 2025
https://github.com/undacmic/heartbleed-proof-of-concept
Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. :old_key: :unlock:
cve-2014-0160 exploit heartbeat heartbleed proof-of-concept tls vulnerability
Last synced: 06 Mar 2026
https://github.com/voidsec/mona-ropshell
For all loaded modules (DLLs), fetch ROP gadgets querying Ropshell DB
corelan exploit exploitation mona rop ropgadget ropshell voidsec
Last synced: 09 Apr 2025
https://github.com/eqstlab/cve-2024-48914
Arbitrary File Read and DoS in vendure-ecommerce exploit
cve exploit poc proof-of-concept security typescript vulnerability
Last synced: 27 Jul 2025
https://github.com/monke443/CVE-2023-40028
Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.
cve cve-2023-40028 exploit ghost-cms github pentesting security vulnerability
Last synced: 30 Aug 2025
https://github.com/sebastian-mora/cve-2020-27358-27359
CVE-2020-27358 and CVE-2020-27359
cve cve-2020-27358 cve-2020-27359 exploit
Last synced: 10 Mar 2025
https://github.com/danucosukosuko/rfsrcexploit
Un nuevo exploit de ChatGPT o una alternativa a D.A.N. Las siglas de RFSR son RE.FU.SE.R. Que se salta la política de OpenAI.
Last synced: 03 Jan 2026
https://github.com/anajuliabit/euler_hack_poc
Euler Incident POC
ethereum evm exploit foundry invariants solidity
Last synced: 18 May 2026
https://github.com/FOGSEC/routersploit
The Router Exploitation Framework
802-11 controller exploit exploitation-framework framework network-analysis network-security python router scanner scanning switch wifi wifi-security wpa wpa2 wps
Last synced: 04 Apr 2025