An open API service indexing awesome lists of open source software.

Exploit

Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.

https://github.com/cr4sh/prl_guest_to_host

Guest to host VM escape exploit for Parallels Desktop

0day exploit hypervisor not-a-bug vulnerability

Last synced: 09 Apr 2025

https://github.com/egebalci/ticketbleed

This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.

exploit f5 ticketbleed tls

Last synced: 18 Nov 2024

https://github.com/xenomega/xsymlink

Xbox One Symbolic Link Exploit: Access restricted/encrypted volumes using the Xbox File Explorer.

csharp exploit hack reverse-engineering symbolic-links vulnerability xbox

Last synced: 30 Jan 2025

https://github.com/knqyf263/cve-2020-10749

CVE-2020-10749 PoC (Kubernetes MitM attacks via IPv6 rogue router advertisements)

exploit ipv6 kubernetes vulnerability

Last synced: 11 Apr 2025

https://github.com/hupe1980/gopwn

Golang CTF framework and exploit development module

binary cave ctf ctf-framework elf exploit golang macho pe shellcode

Last synced: 16 Apr 2025

https://github.com/farisv/appledos

Messing Apple devices on the network with CVE-2018-4407 (heap overflow in bad packet handling)

apple dos-attack exploit

Last synced: 10 Apr 2025

https://github.com/knqyf263/CVE-2020-10749

CVE-2020-10749 PoC (Kubernetes MitM attacks via IPv6 rogue router advertisements)

exploit ipv6 kubernetes vulnerability

Last synced: 17 Nov 2024

https://github.com/cawfree/sameorigin

๐Ÿค– ๐Ÿงช Masquerade as if you were their own frontend.

axios blur bypass cloudflare cors exploit marketplace nft opensea puppeteer

Last synced: 10 Apr 2025

https://github.com/mauricelambert/cve-2022-21907

CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube.

bluescreen crash cve cve-2022-21907 denial-of-service detection dos exploit iis metasploit microsoft nmap payload powershell protection python3 ruby vulnerability webserver

Last synced: 11 Apr 2025

https://github.com/inndy/formatstring-exploit

Dead simple format string exploit payload generator

ctf exploit printf

Last synced: 25 Apr 2025

https://github.com/000pp/WSOB

๐Ÿ˜ญ WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.

cve-2022-29464 exploit python wso2

Last synced: 17 Apr 2025

https://github.com/nullarray/shellshocker

A Bash script to test a list of URLs for the shellshock vulnerability.

bash exploit pentest pentesting shell shellshock-vulnerability

Last synced: 13 Apr 2025

https://github.com/software-engineering-and-security/inspector-gadget

Inspector-gadget (a.k.a. PSHAPE - Practical Support for Half-Automated Program Exploitation) is an open source tool which assists analysts in exploit development. It discovers gadgets, chains gadgets together, and ensures that side effects such as register dereferences do not crash the program.

exploit gadget-chain gadgets inspector-gadget pshape register vulnerability

Last synced: 15 Apr 2025

https://github.com/limbenjamin/LogServiceCrash

POC code to crash Windows Event Logger Service

crash eventlog exploit windows

Last synced: 21 Nov 2024

https://github.com/0xAsuka/shu-shell

Webshell Jumping Edition

exploit file-manager symlink webshell

Last synced: 17 Nov 2024

https://github.com/jcubic/jsh.php

Terminal like php shell (PHP+jQuery WebShell)

exploit jquery jquery-plugin shell terminal-app vulnerability web-shell web-terminal

Last synced: 14 Apr 2025

https://github.com/karthikuj/cve-2022-31101

Exploit for PrestaShop bockwishlist module 2.1.0 SQLi (CVE-2022-31101)

blockwishlist cve-2022-31101 exploit prestashop

Last synced: 09 Feb 2025

https://github.com/m3ssap0/gitlab_rce_cve-2022-2884

Exploits GitLab authenticated RCE vulnerability known as CVE-2022-2884.

cve-2022-2884 exploit gitlab security security-tools vulnerability vulnerability-scanners

Last synced: 04 May 2025

https://github.com/johnoseni1/router-hacker-exploit-and-extract-user-and-password-

This is a python wifi (router) hacker , having ability to search for mikrotic devices around you and get their <MAC> address then extract their user and password

exploit hacking ipaddress macaddress mikrotik port python safety

Last synced: 14 Feb 2025

https://github.com/adamyordan/offbyslash-django-dumper

A proof of concept to dump Django website's source code affected by NGINX's off-by-slash alias directive misconfiguration.

django dumper exploit nginx poc security source-code vulnerability web-security

Last synced: 12 Apr 2025

https://github.com/3ndg4me/cve-2020-3452-exploit

Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.

bash cisco cve cve-2020-3452 exploit hacktoberfest shell vulnerability

Last synced: 25 Mar 2025

https://github.com/rek7/zimbra-rce

Zimbra RCE PoC - CVE-2019-9670 XXE/SSRF

exploit python rce zimbra

Last synced: 30 Apr 2025

https://github.com/nullarray/shellware

Persistent bind shell via pythonic shellcode execution, and registry tampering.

exploit pentest pentesting-windows persistence shellcode

Last synced: 13 Apr 2025

https://github.com/simonuvarov/expdev

Vulnerable software and exploits used for OSCP/OSCE preparation

corelan exploit osce oscp

Last synced: 18 Nov 2024

https://github.com/iricartb/advanced-sql-injection-scanner

Ivan Ricart Borges - Test for didactic purposes of web pages vulnerables to SQL injection using dbo database user with xp_cmdshell execution permissions. Using patterns from Internet search engines to extract potentially vulnerable web addresses and test them by changing the GET parameters using invalid Transact-SQL conversion function to cause through unhandled errors by IIS web server to show critical information. If certain features are given and using advanced injection techniques a malicious attacker could gain control of the entire system by executing shell commands in the SQL database engine.

c-sharp database dbo exploit iis injection microsoft rce scanner search-engine sqlserver transact-sql visual-studio vulnerability webserver xp-cmdshell

Last synced: 10 Apr 2025

https://github.com/kotvnaskehitman4/nebula-executor

Nebula is a new Lua executor for Roblox. It's simple, straightforward, we ensure quick patches after Roblox updates.

bloxfruits-script cheat discord exploit exploiting lua roblox roblox-lua roblox-script roblox-scripts roblox-studio robloxdev rojo script

Last synced: 06 Dec 2024

https://github.com/jm33-m0/cve-2018-7750

an RCE (remote command execution) approach of CVE-2018-7750

cve-2018-7750 exploit poc

Last synced: 08 Apr 2025

https://github.com/b4zinga/explib

Explib: Collections of poc and exp.

exploit poc python tools

Last synced: 18 Nov 2024

https://github.com/k8gege/jbossexploit

MSF moudle jboss invoke deploy getshell Exploit & Jboss jmx-console getshell exploit

exp exploit getshell jboss metasploit msf poc rce

Last synced: 03 May 2025

https://github.com/davidbuchanan314/wifi-sdcf

Reverse Engineering notes on the Dxingtek/Keytech(?) WiFi@SDCF card

exploit iot reverse-engineering

Last synced: 12 Apr 2025

https://github.com/paulveillard/cybersecurity-exploit-development

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Exploit Development.

code-execution developer developer-experience developer-tools development development-tools exploit exploitation exploitation-framework exploitation-frameworks exploitation-menu vulnerability-detection

Last synced: 28 Mar 2025

https://github.com/joseph21v/roblox-incognito

Incognito is a Roblox script executor known for its user-friendly interface and support for executing Lua scripts, providing enhanced gameplay and automation features. Regular updates ensure compatibility with Roblox's latest changes, though using it risks violating Roblox's terms of service.

exploit incognito incognito-crash incognito-discord incognito-download incognito-external incognito-fix incognito-key incognito-no-key incognito-update incognito-v2-download inkognito roblox roblox-incognito

Last synced: 22 Feb 2025

https://github.com/hugsy/hevd

Public repository for HEVD exploits

exploit hacksys hevd kernel pwn windbg windows

Last synced: 10 Apr 2025

https://github.com/kia87v73/roblox-bunni-executor

Bunni is a premier Roblox exploiting platform, renowned for its cutting-edge tools, rapid updates, and robust support. Developed by experienced professionals, it ensures maximum efficiency, security, and a seamless user experience with features like HWID spoofer and extensive script support.

cheats code developer exploit gaming github hacking injector lua modding open-source programming project

Last synced: 30 Dec 2024

https://github.com/cokebeer/go-cves

ๆ”ถๅฝ•go่ฏญ่จ€็ผ–ๅ†™็š„้กน็›ฎใ€ๆก†ๆžถๅ’Œ็ป„ไปถๅ‡บ็Žฐ็š„cve๏ผŒๆˆ–่€…ไธ€ไบ›็›ธๅ…ณ็š„ๅˆฉ็”จๆ–นๅผ็š„ๆ–‡็ซ 

bugbounty cve exploit go poc security

Last synced: 02 Dec 2024

https://github.com/notselwyn/exploits

Custom exploits

exploit linux proof-of-concept

Last synced: 27 Dec 2024

https://github.com/deepsyx/vote-buster

Capcha+Email confirmation bypass script

bot bypass captcha cookie exploit recognization smtp-server tesseract

Last synced: 19 Apr 2025

https://github.com/nikewaybuck/nebula-executor

Nebula is a new Lua executor for Roblox. It's simple, straightforward, we ensure quick patches after Roblox updates.

bloxfruits-script cheat discord exploit exploiting lua roblox roblox-lua roblox-script roblox-scripts roblox-studio robloxdev rojo script

Last synced: 09 Apr 2025

https://github.com/sgabe/cve-2019-1253

AppXSvc Arbitrary File Security Descriptor Overwrite EoP

elevation-of-privilege eop exploit proof-of-concept vulnerability windows10

Last synced: 14 Dec 2024

https://github.com/tatapinhighcone74/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

authentication bloxfruit-script bloxfruits-autofarm-script executer exploit game gui hack lua nexus-roblox roblox roblox-lua roblox-script roblox-scriptbloxfruits-autofarm-script roblox-scripts roblox-synapse robloxscripts script-hub supported whitelist

Last synced: 23 Apr 2025

https://github.com/thewhiteh4t/cve-2020-9375

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.

cve cve-2020-9375 exploit tp-link tplink

Last synced: 12 Apr 2025

https://github.com/xsscx/cve-2017-5638

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit

apache code content-type cve-2017-5638 exploit poc python struts2

Last synced: 26 Apr 2025

https://github.com/warflop/iot-mqtt-exploit

An tool for search IOT MQTT vulnerable with shodan

exploit iot mqtt shodan

Last synced: 15 Dec 2024

https://github.com/mustafadalga/multi-client-reverse-shell

A multi-client reverse shell that allows multiple connections from target computers || Hedef bilgisayarlardan gelen birden fazla baฤŸlantฤฑya izin veren รงoklu istemcili reverse shell.

exploit hack hacking hacking-attack-tools hacking-code hacking-tool hacking-tools multi-reverse-shell python-for-hacking python-for-security python-reverse-shell python3 reverse-shell shell shell-script shell-scripts shellcode shellscript

Last synced: 15 Apr 2025

https://github.com/camiloczz/scriptware

Scriptware Executor is a premium Roblox tool for Windows and macOS, renowned for its ability to execute Lua scripts efficiently, offering robust features for advanced game modifications and seamless gameplay enhancements.

backup borgbackup delayless exploit fe fluxus hack http krnl lua netbypass netless reanimate rest-api roblox rust script scriptware synapse tauri

Last synced: 12 Apr 2025

https://github.com/givenam/codex-roblox

Roblox Codex Executor supports low-end PCs and let you enjoy the stable and smooth. Codex stands out as the premier Roblox script executor, providing unparalleled functionality to effortlessly run scripts for your preferred Roblox games.

codex codex-roblox executer exploit game gui hack lua roblox script-hub supported trigon-download trigon-evo trigon-evo-download trigon-key trigon-script

Last synced: 15 Feb 2025

https://github.com/mustafadalga/code-injector

Aynฤฑ aฤŸ iรงerisinde , ARP Spoofing saldฤฑrฤฑsฤฑ yapฤฑlmฤฑลŸ hedef bilgisayarฤฑn ziyaret ettiฤŸi , HTTP protokolรผnรผ kullanan web sitelerine kod enjekte ederek manipรผle etmenize yarayan bir script.

code-injection cyber-security cyber-threat-intelligence cybersecurity exploit hacker hacking hacking-code hacking-tool hacking-tools hackingtools python python-3 python-script python3 web-hackathon web-hacking website-hacking

Last synced: 30 Apr 2025

https://github.com/emo-crab/scap-rs

National Vulnerability Database (NVD) implemented by rust

actix-web cpe cve cvss cvssv3 cvssv4 cwe exploit nuclei-templates nvd rust scap yew

Last synced: 11 Apr 2025

https://github.com/seclab-ucr/syzbridge

SyzBridge is a research project that adapts Linux upstream PoCs to downstream distributions. It provides rich interfaces that allow you to do a lot of cool things with Syzbot bugs

bug-triage exploit linux linux-kernel

Last synced: 22 Nov 2024

https://github.com/0xinfection/epscalate

Exploit for elevation of privilege vulnerability in QuickHeal's Seqrite EPS (CVE-2023-31497).

cve-2023-31497 endpoint-security exploit privilege-escalation

Last synced: 13 Apr 2025

https://github.com/egebalci/msf-self-defence

Self defense post module for metasploit

anti-detection defense exploit

Last synced: 18 Nov 2024

https://github.com/aydinnyunus/cve-2024-24576-exploit

CVE-2024-24576 Proof of Concept

1-day exploit rust security

Last synced: 29 Apr 2025

https://github.com/owlinux1000/arm_exploit

ARM Exploit ้–‹็™บใฎใŸใ‚ใฎใƒˆใƒฌใƒผใƒ‹ใƒณใ‚ฐใƒชใƒใ‚ธใƒˆใƒช

arm exploit

Last synced: 15 Nov 2024

https://github.com/yallxe/hogg

Common vulnerability scanning on steroids โ˜„๏ธ

dns exploit network proxy rust rust-lang scanner secrets security sniffer vulnerabilities webscanner

Last synced: 26 Nov 2024

https://github.com/000pp/pwnfaces

๐Ÿ˜› Primefaces 5.X EL Injection Exploit (CVE-2017-1000486)

cve cve-2017-1000486 elinjection exploit golang linux primefaces redteam

Last synced: 24 Apr 2025

https://github.com/mlgmxyysd/f21proinjector

Exploit the vulnerability to install arbitrary applications in k61v1 without ROOT

android exploit exploitation hacking hacktoberfest php

Last synced: 07 May 2025

https://github.com/thewhiteh4t/cve-2021-31630

Python script for exploiting command injection in Open PLC Webserver v3

cve exploit openplc rce

Last synced: 12 Apr 2025

https://github.com/LukeBob-zz/C2-Pwn

Uses Shodan API to pull down C2 servers to run known exploits on them.

c2 exploit python rat shodan-api

Last synced: 17 Nov 2024

https://github.com/m3ssap0/spring-break_cve-2017-8046

This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).

cve-2017-8046 exploit security security-tools spring-break spring-data-rest vulnerability vulnerability-scanners

Last synced: 04 May 2025

https://github.com/rxzyx/ttrockstars-hacks

The best hack for times tables rock-stars ever.

cheat exploit javascript ttrockstars

Last synced: 01 Apr 2025

https://github.com/ait-testbed/attackmate

AttackMate is an attack orchestration tool that executes full attack-chains based on playbooks.

api attack automation automation-framework cybersecurity exploit metasploit orchestration pentest python redteam rootkit security sliver testbed training

Last synced: 22 Apr 2025

https://github.com/tiotails22/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

bloxfruit-script exploit lua roblox roblox-electron roblox-electron-free roblox-electron-script roblox-electron-scripts roblox-electron-v3 roblox-execute roblox-executer roblox-executer-solara roblox-script roblox-scripts roblox-solara roblox-solara-free roblox-solara-key roblox-synapse roblox-synapsex roblox-synapsex-free

Last synced: 15 Feb 2025

https://github.com/bcoles/serenity-exploits

Various exploits for SerenityOS

exploit serenityos

Last synced: 25 Mar 2025

https://github.com/p0dalirius/binaryexploitation

A massive documentation about binary protections, exploitation techniques, and computer architecture concepts.

binary buffer exploit exploitation overflow pwn system

Last synced: 04 Apr 2025

https://github.com/Warflop/IOT-MQTT-Exploit

An tool for search IOT MQTT vulnerable with shodan

exploit iot mqtt shodan

Last synced: 17 Nov 2024

https://github.com/m8sec/eaprimer

C# project to Reflectively load .Net assemblies in memory

amsi csharp executing-assemblies exploit net-assemblies pentesting powershell windows

Last synced: 26 Mar 2025

https://github.com/mido21102/xeno-executor

Xeno-Executor is a powerful open-source automation tool designed to simplify and streamline the execution of tasks and processes.

csharp delta-exploits exploit ldplayer lua luau roblox roblox-lua roblox-menu roblox-script roblox-scripts roblox-xeno xeno-executor xeno-roblox

Last synced: 22 Apr 2025

https://github.com/0x00-0x00/cve-2016-2098

Ruby On Rails unrestricted render() exploit

exploit rail rails render ruby

Last synced: 22 Nov 2024

https://github.com/gousaiyang/pickleassem

A simple pickle assembler to make handcrafting pickle bytecode easier.

assembler bytecode ctf exploit pickle security security-tools

Last synced: 13 Apr 2025

https://github.com/paradiseduo/ttnetworkmanager

SSL pinning that TikTok/ๆŠ–้Ÿณ

bypass douyin exploit payload tiktok

Last synced: 11 Apr 2025

https://github.com/byt3n33dl3/camhoundad

Automated Exploit scanners for public Camera, CCTV's, and Capture Devices.

camera cctv exploit surveillance trust-attack

Last synced: 19 Dec 2024

https://github.com/3kh0/chromeos-playstore

Step by step guide on how to get the playstore on your Chromebook!

chromeos chromeos-flex exploit playstore unblocker

Last synced: 15 Apr 2025

https://github.com/jonoans/umbraco-rce

Umbraco CMS 7.12.4 - (Authenticated) Remote Code Execution

exploit poc proof-of-concept python3 rce remote-code-execution umbraco-cms umbraco-v7

Last synced: 14 Apr 2025

https://github.com/qkaiser/voodoo

This repository holds proof-of-concepts for the VOOdoo vulnerabilities found in NETGEAR CG3100 and CG3700B cable modems provided by VOO to its subscribers.

cg3100 cg3700 exploit netgear voo wireless

Last synced: 16 Dec 2024

https://github.com/CnHack3r/Penetration_PoC

FROM:@Mr-xn ๆธ—้€ๆต‹่ฏ•ๆœ‰ๅ…ณ็š„POCใ€EXPใ€่„šๆœฌใ€ๆๆƒใ€ๅฐๅทฅๅ…ท็ญ‰---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss penetration-testing-poc csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

bypass cms-exploits cms-framework cobaltstrike cve exploit rce sql-scanner

Last synced: 10 Mar 2025

https://github.com/0x00-0x00/-cve-2017-9805

Exploit script for Apache Struts2 REST Plugin XStream RCE (โ€ŽCVE-2017-9805)

apache cve exploit struts

Last synced: 22 Nov 2024

https://github.com/krishpranav/exploit-framework

A multiple reverse shell sessions/clients manager via terminal written in go

ctf exploit exploit-framework exploitation go golang reverse-shell reverse-shell-as-a-service

Last synced: 15 Apr 2025

https://github.com/0xricksanchez/sploitget

A wrapper script for https://sploitus.com to scrape query results for tools and exploits

ctf exploit exploitation pentest-tool security wrapper-api

Last synced: 13 Apr 2025

https://github.com/jaydenth/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

authentication bloxfruit-script bloxfruits-autofarm-script executer exploit game gui hack lua nexus-roblox roblox roblox-lua roblox-script roblox-scriptbloxfruits-autofarm-script roblox-scripts roblox-synapse robloxscripts script-hub supported whitelist

Last synced: 26 Mar 2025

https://github.com/z3k0sec/cve-2024-9264-rce-exploit

Grafana RCE exploit (CVE-2024-9264)

cve-2024-9264 duckdb exploit grafana rce shellfs

Last synced: 15 Mar 2025

https://github.com/uni-due-syssec/teerex-exploits

PoC exploits against various SGX enclaves

exploit memory-corruption poc sgx

Last synced: 20 Apr 2025