Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
Exploit
Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.
- GitHub: https://github.com/topics/exploit
- Wikipedia: https://en.wikipedia.org/wiki/Exploit_(computer_security)
- Created by: The cybersecurity community
- Related Topics: hacking, cybersecurity, penetration-testing, vulnerability-assessment,
- Aliases: exploits, vulnerability-exploit,
- Last updated: 2025-02-13 00:10:18 UTC
- JSON Representation
https://github.com/alwalxed/juicyurls
A CLI tool to scan suspicious URLs by keywords, extensions, paths and hidden files.
automation bugbounty cli cybersecurity detection exploit golang malware open-source osint penetration-testing projectdiscovery recon reconnaissance scanner scanning security urlscan vulnerabilities
Last synced: 15 Nov 2024
https://github.com/a0zhar/ps4payloadloader
This repository will be maintained by me. Super simple to use! It has everything needed to build Your own MiraLoader or Payload Launcher refrenced in the PS4JB Repo by Sleirsgoevy
c exploit freebsd playstation4 ps4 ps4-jailbreak ps4-payload ps4exploit ps4jb ps4payload
Last synced: 20 Jan 2025
https://github.com/piotrbania/apple_exploit_talos-2016-0088
apple exploit TALOS-2016-0088
apple exploit hacking macos null-pointer-dereferences
Last synced: 21 Jan 2025
https://github.com/p1ckzi/cve-2022-35513
CVE-2022-35513 | blink1-pass-decrypt
blink1-pass-decrypt blink1control2 cve cve-2022-35513 exploit
Last synced: 30 Jan 2025
https://github.com/hunthubspace/cve-2024-0757-exploit
A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)
bugbounty cve ethical-hacking exploit penetration-testing web
Last synced: 31 Jan 2025
https://github.com/monke443/cve-2023-40028-ghost-arbitrary-file-read
Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.
cve cve-2023-40028 exploit ghost-cms github pentesting security vulnerability
Last synced: 27 Dec 2024
https://github.com/typicalmodmaker/cve-2024-4956
Proof-Of-Concept (POC) for CVE-2024-4956
cve cve-2024-4956 exploit poc proof-of-concept proofofconcept vulnerability
Last synced: 07 Nov 2024
https://github.com/drdataye/drxploit
DrXploit is a powerful and open-source penetration testing and exploitation tool for web applications. This tool is designed to automate the process of discovering and exploiting vulnerabilities, saving time and effort for security researchers.
bugbounty exploit exploit-db hacking hacking-tool hackweb python3 scanning
Last synced: 20 Nov 2024
https://github.com/x86-512/vxpp
A VFGadget finder script to facilitate Counterfeit Object-Oriented Programming (COOP) and Loop-Oriented Programming (LOP) attacks to bypass advanced security protections like CET and CFG.
binary-exploitation buffer-overflow code-reuse control-flow-guard control-flow-integrity coop exploit exploit-development intel-cet lop rop rop-gadgets ropgadget security-bypass uaf use-after-free
Last synced: 11 Nov 2024
https://github.com/renatoalencar/dlink-dir610-exploits
Exploits for CVE-2020-9376 and CVE-2020-9377
authentication-bypass dlink exploit remote-code-execution
Last synced: 07 Nov 2024
https://github.com/tigerclips1/ps4jb_update_downloader_usb
What this script does is auto download ps4JB updates that you choose to your USB automation for linux only
automation exploit firmware guide linux ps4 ps4-jailbreak python python-script python3 tigerclips1
Last synced: 07 Jan 2025
https://github.com/kernelerr/vlc-cve-2008-4654-exploit
An EXP could run on Windows x64 against CVE-2008-4654.
cve exploit out-of-memory vlc vlc-media-player
Last synced: 19 Jan 2025
https://github.com/examplest/uac-bypass-fud
UAC bypass, Elevate, Persistence methods
administrator-privileges bypass-uac dll-hijacking exploit fodhelperbypass fud hacking uac-bypass uacme user-account-control windows
Last synced: 08 Dec 2024
https://github.com/randomrobbiebf/cve-2023-0630
CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection
cve-2023-0630 exploit wordpress wordpress-plugin
Last synced: 21 Jan 2025
https://github.com/randomrobbiebf/cve-2024-0679
ColorMag <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
cve-2024-0679 exploit wordpress
Last synced: 21 Jan 2025
https://github.com/masasron/chameleondump
Dump RFID tag IDs from ChameleonUltra devices
Last synced: 22 Nov 2024
https://github.com/m3hu1/speedtyperexploit
speedtyper.dev exploit written in python
Last synced: 15 Jan 2025
https://github.com/kaanaryoverflow/ipfire-2-25-auth-rce
ipfire 2.25 authenticated remote code execution
Last synced: 05 Feb 2025
https://github.com/lucabarile/zdi-can-16857
Exploit and report for CVE-2023-32163
0-day 0day bugbounty cve-2023-32163 disclosure elevation-of-privilege exploit local-privilege-escalation logical-vulnerability lpe poc privilege-escalation proof-of-concept vulnerability wacom wacom-driver wacom-vulnerability write-up writeups zdi-can-16857
Last synced: 31 Dec 2024
https://github.com/codeb0ss/cve-2024-1698-poc
Mass Exploit CVE-2024-1698 - Wordpress NotificationX <= 2.8.2 - SQL Injection
codeb0ss codeboss cve-2024 cve-2024-1698 cve-2024-1698-exp cve-2024-1698-poc exploit wordpress
Last synced: 13 Nov 2024
https://github.com/codeb0ss/cve-2024-29824-poc
Mass Exploit - CVE-2024-29824 - Ivanti EPM - Remote Code Execution (RCE)
codeb0ss cve cve-2024-29824 cve-2024-29824-exp cve-2024-29824-exploit cve-2024-29824-poc exploit ivanti ivanti-rce rce remote-code-execution uncodeboss
Last synced: 13 Nov 2024
https://github.com/eqstlab/cve-2024-48914
PoC for CVE-2024-48914
cve exploit poc proof-of-concept security typescript vulnerability
Last synced: 02 Dec 2024
https://github.com/n3rada/zero-effort
Exploiting CVE-2020-1472 vulnerability (a.k.a Zerologon) without effort.
active-directory cve-2020-1472 evil-winrm exploit impacket-secretsdump windows zerologon
Last synced: 28 Dec 2024
https://github.com/krishpranav/exploitdb
Golang tool to search exploits from exploitdb
database db ethical exploit exploitation exploitdb go golang hacking information license mit mongodb open-source osint sqlite
Last synced: 01 Feb 2025
https://github.com/dubniczky/kernel-exploits
Kernel exploits consisting mostly of privilege escalation attacks against core components of Linux distribtions
cve exploit linux linux-exploits linux-kernel
Last synced: 06 Feb 2025
https://github.com/p1ckzi/cve-2017-9841
phpunit-shell | CVE_2017-9841
cve-2017-9841 exploit hacking pentesting phpunit phpunit-shell rce
Last synced: 06 Feb 2025
https://github.com/p1ckzi/nanocmshell
authenticated remote code execution via shell upload.
exploit file-upload nanocms nanocmshell php php-reverse-shell rce
Last synced: 06 Feb 2025
https://github.com/jenderal92/git-dump
This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and 'BeautifulSoup', this script examines the directory structure, downloads files, and identifies SHA-1 hashes within Git files.
exploit git git-download git-dumper git-dumper-python git-exposed git-vulnerability python python-git-dumper vulnerability vulnerability-git
Last synced: 13 Feb 2025
https://github.com/jker768/deadlock-external-cheat
Γ°ΕΈβΒ± Deadlock: Wallhack, AimBot, AimBot Soul, RCS, Radar
anti-cheat cheat code deadlock detection exploit external fair-play game-mods github hacking integrity mitigation multiplayer prevention protection reverse-engineering security software validation
Last synced: 13 Feb 2025
https://github.com/lololosys/exploitation_notes
This repository contain common exploitation primites for various platforms
Last synced: 02 Feb 2025
https://github.com/ytisf/snmplicity
the Swiss Army Knife of the SNMP world, but, it's coded in Python, not made of stainless steel!
cisco code-execution exploit redteam-tools redteaming snmp
Last synced: 05 Feb 2025
https://github.com/zeyad-azima/opayforme
CVE-2021-43150 Exploit for `opay` android app webview
Last synced: 09 Feb 2025
https://github.com/r-teamdev/rcheat-injector
exploit game-haking injector lua rcheat-injector roblox roblox-lua roblox-script scripts
Last synced: 14 Oct 2024
https://github.com/retr0kr0dy/malloc-bomb
Presenting the latest Linux bomb exploit: not a fork but a malloc-based threat. Delve into the intricacies of this novel vulnerability.
coding cybersecurity denial-of-service dos exploit forkbomb hacking infosec linux malloc pentesting security system-exploitation vulnerability
Last synced: 23 Dec 2024
https://github.com/miguelzacca/afs
Redirection of sensitive form data to a remote server. Self-XSS
cheat dom-manipulation dommanipulation exploit google-hacking googlehacking hacking javascript js json ngrok node nodejs self-xss server vulnerability xss xss-injection
Last synced: 23 Dec 2024
https://github.com/whokilleddb/cve-2019-15107
CVE-2019-15107 Webmin Exploit in C
Last synced: 01 Jan 2025
https://github.com/al1ex/cve-2021-3317
CVE-2021-3317
cve-2021-3317 exploit klogserver
Last synced: 14 Feb 2025
https://github.com/p1ckzi/CVE-2012-5519
cups-root-file-read.sh | CVE-2012-5519
cups-root-file-read cve cve-2012-5519 cves exploit hacking pentesting-tools
Last synced: 23 Oct 2024
https://github.com/lynk4/cve-2011-2523
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
cve cve-2011-2523 exploit metasploitable metasploitable-2 metasploitable-3 python vsftpd-exploit
Last synced: 01 Jan 2025
https://github.com/5amu/pocbrowser
Scrape websites to find PoCs for CVEs
crystal crystal-lang cve cybersecurity exploit pentesting proof-of-concept scraping security-tool security-tools vulnerability-assessment
Last synced: 07 Feb 2025
https://github.com/nhas/cve-2024-45337-poc
Proof of concept (POC) for CVE-2024-45337
cve cve-2024-45337 exploit golang hack pentesting poc proof-of-concept ssh
Last synced: 22 Dec 2024
https://github.com/yoramvandevelde/wp-cli_attack_object_cache
Attacking hosting webservers through WP-CLI
exploit hacking pentesting social-engineering-attacks wordpress wpcli
Last synced: 25 Jan 2025
https://github.com/kissssu/ftp-exploit-vsftpd-2.3.4-backdoor
Python script for exploiting a specific vulnerability in vsFTPd 2.3.4.
Last synced: 06 Jan 2025
https://github.com/the-wagonization/the-wagon-site
Repository for The Wagon Site's code
bookmarklets chrome chrome-os chrome-os-exploits chros exploit exploits games proxies proxy school school-exploit school-exploits windows windows-10 windows-10-exploit windows-10-exploits windows-11 windows-11-exploit windows-11-exploits
Last synced: 06 Feb 2025
https://github.com/atls0572212529/rafel-rat--9637-
-------> RAFEL<------ Android Rat Written in Java With WebPanel For Controlling Victims...Hack Android Devices
android android-hack-rat android-rat android-remote anti-vm bypass-vm device-management exploit hack-android hacking hacking-tool java-rat pentestin pentesting pentesting-android php-rat remote-access-tool remote-access-trojan
Last synced: 27 Dec 2024
https://github.com/mxlgv/toaruos-exploits
This is a repository with exploits for ToaruOS.
exploit privelegeescalation toaruos vuln
Last synced: 09 Feb 2025
https://github.com/s1lkys/cve-2021-24884
If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in Formidable Forms 4.09.04.
exploit formidable wordpress xss
Last synced: 07 Feb 2025
https://github.com/jenderal92/chamilo-cve-2023-34960
Wordpress CVE-2023-34960
cve-2023-34960 exploit exploit-wordpress vulnerability wordpress wordpress-vulnerability
Last synced: 21 Dec 2024
https://github.com/codeb0ss/cve-2024-25735-poc
CVE-2024-25735 - WyreStorm Apollo VX20 - Information Disclosure
codeb0ss cve cve-2024 cve-2024-25753 cve-2024-25753-exp cve-2024-25753-poc exploit exploits uncodeboss vulnerability
Last synced: 12 Jan 2025
https://github.com/jenderal92/wp-cve-2023-28121
Wordpress CVE-2023-28121
bot-auto-scanner-vuln bot-auto-upload-shell cve-2023-28121 cve-wordpress exploit vulnerability wordpress
Last synced: 21 Dec 2024
https://github.com/kdandy/pentest_tools
WebTest Tools
blueteam cybersecurity exploit pentest pentesting redteam security-tools shell tools website
Last synced: 21 Jan 2025
https://github.com/vaibhavpandeyvpz/dtp-exploit-poc
Simple and single purpose PoC app built using React Native to demonstrate PII leak vulnerability in Delhi Traffic Police's notice payment website.
exploit information leak privacy security vulnerability
Last synced: 02 Jan 2025
https://github.com/p1ckzi/cve-2009-2265
cf8-upload.py | CVE-2009-2265
cf8-upload cve cve-2009-2265 exploit hacking pentesting-tools
Last synced: 06 Feb 2025
https://github.com/Fadavvi/CVE-2018-17431-PoC
Proof of consept for CVE-2018-17431
comodo cve cve-2018-17431 exploit poc proof-of-concept rce remote-code-execution
Last synced: 23 Oct 2024
https://github.com/devvyyxyz/devvyys-scripts
Roblox exploit scripts by Devvyyxyz
exploit roblox-cheat roblox-executor roblox-hack script
Last synced: 09 Feb 2025
https://github.com/franckferman/glpi-htmlawed-cve-2022_35914-poc
Automatic scanning (Shodan) and exploitation (PoC) script for the GLPI htmLawed vulnerability (CVE-2022_35914).
bash exploit glpi poc proof-of-concept python python3 remediation shell shodan vuln vulnerabilities vulnerability vulnerability-detection vulnerability-scanning
Last synced: 19 Jan 2025
https://github.com/prvvv/chromeforensics
Different code samples for Chrome browser analysis & post exploitation
chrome chrome-devtools exploit forensic forensics forensics-tools hacking password post-exploitation
Last synced: 23 Jan 2025
https://github.com/jenderal92/csrf-exploit-generator
The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.
csrf csrf-generator exploit penetration-testing python-27 security-testing-tools web-security
Last synced: 13 Feb 2025
https://github.com/ahmed-alnassif/pwnxss
PwnXSS: Vulnerability (XSS) scanner exploit
beautifulsoup4 exploit fake-useragent pwnxss python3 requests scanner security security-tools threads vulnerability xss xss-scanner
Last synced: 16 Jan 2025
https://github.com/hunthubspace/subscope
SubScope is a Python-based command-line tool that helps you manage domains and subdomains in workspaces using an SQLite database.
automation bugbounty bugbounty-tool database ethical-hacking exploit penetration-testing python sqlite web web-penetration-testing
Last synced: 31 Jan 2025
https://github.com/codingchili/cve-2020-14368
Interactive RCE exploit demo for Eclipse CHE
eclipse-che exploit proof-of-concept vulnerability
Last synced: 12 Feb 2025
https://github.com/langriklol/cve-2020-15227
CVE-2020-15227 exploit
exploit rce security vulnerability
Last synced: 18 Jan 2025
https://github.com/upcraftlp/upsidedown
Minecraft mod that focuses on the looks of the Minecraft client.
client client-side cosmetic cosmetics exploit exploitation exploits forge forge-mod minecraft minecraft-client minecraft-forge minecraft-mod minecraftforge
Last synced: 13 Feb 2025
https://github.com/caenjones/codespaces-desktop
Web-based operating system running in Github Codespaces!
bypass codespaces exploit github kasmvnc proxy
Last synced: 11 Nov 2024
https://github.com/rsrdesarrollo/auto-ysoserial
Generate all ysoserial payloads with burp collaborator (or similar)
burp burpsuite exploit java python security security-tools ysoserial
Last synced: 11 Feb 2025
https://github.com/francescodisalesgithub/downloadsploit
QuickScript to download exploits from exploitdb
download download-exploits exploit exploitdb exploits hacking hacking-tool metasploit quickscript searchsploit
Last synced: 28 Jan 2025
https://github.com/mauricelambert/pywcgishell
This package implement a WebShell for CGI and WSGI server.
cgi-script exploit pypi-package python3 web-attacks webshell wsgi-server
Last synced: 14 Jan 2025
https://github.com/javierolmedo/check-ms17-010
π Simple script in powershell to check ms17-010 vulnerability exploited by ransomware WannaCry
exploit ms17-010 powershell powershell-script script vulnerability wannacry
Last synced: 28 Jan 2025
https://github.com/shamo0/CVE-2022-1388
BIG-IP iControl REST vulnerability CVE-2022-1388 PoC
1388 2022 bash bigip cve cve-2022-1388 exploit f5 icontrol python rest script shell vulnerabilit
Last synced: 23 Oct 2024
https://github.com/darksel0/js-keylogger
exploit fud-keylogger javascript keyboard keylogger malware rat rat-fud remote-access-tool
Last synced: 05 Jan 2025
https://github.com/bstyls/winrar-exploit-builder
The WinRAR Exploit Builder is a C# project designed to create an exploit targeting a vulnerability in WinRAR.
0day 0day-2024 0day-exploit 0day-exploits archive aslr-bypass cve exploit exploit-database exploit-development exploit-kit pdf pdf-exploit pdf-format rce-exploit security winrar winrar-exploit zero-day-exploit zeroday-attack
Last synced: 08 Feb 2025
https://github.com/darksel0/bypassddos
cf-bypass ddos ddos-script ddos-tool ddoser-tool exploit js layer7-ddos layer7bypass
Last synced: 05 Jan 2025
https://github.com/mykhis/jpg-png-exploit-slient-builder-exploit-database-cve-2023-malware
In the hushed galleries of the Silent JPG Exploit, a symphony shrouded in enigma unfurlsβan opus named silent-jpg-exploit-2018βa title that reverberates through the annals of intrigue.
cve cve-2021-44228 cve-scanning exploit exploit-code exploit-database exploit-development exploit-exercises exploit-kit exploitation exploitation-framework slient-doc-exploit slient-exploit slient-exploit-builder slient-hta-exploit slient-jpg-exploit slient-pdf-exploit slient-png-exploit slient-url-exploit
Last synced: 28 Jan 2025
https://github.com/darksel0/slowloris
browser-ddos ddos-attack-tools ddos-attacks ddos-script-tool ddos-scripts ddos-software dos dos-attack dos-attack-tool exploit flooder layer7 layer7-ddos layer7-flood norussia stoprussia stoprussianaggression stoprussionagression stresser
Last synced: 05 Jan 2025
https://github.com/pandh4cker/pandagik
Image Magick Exploit for CVE-2016β3714
exploit imagemagick python3 rce
Last synced: 18 Jan 2025
https://github.com/anshvaid4/follinatest
Reference of code has been taken from https://github.com/JohnHammond/msdt-follina/blob/main/follina.py. I have given the explanation of the code and made the code a bit simplified.
Last synced: 01 Feb 2025
https://github.com/s1lkys/cve-2021-40101
Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4
concrete5 cve-2021-40101 exploit xss
Last synced: 01 Feb 2025
https://github.com/arshtepe/jenkins-serialization-vulnerability-exploit
exploit for jenkins
Last synced: 01 Feb 2025
https://github.com/hunthubspace/torwatch
TorWatch is a powerful bash script for monitoring the availability of websites through the Tor network. It manages IP address rotation, blocks IP addresses if the site is inaccessible, and logs activities for tracking events.
bash-scripting bugbounty exploit penetration-testing tor web-penetration-testing
Last synced: 31 Jan 2025
https://github.com/piotrbania/vmware_exploit_pack_cve-2009-1244
vmware cloudburst exploit CVE-2009-1244
exploit guest-to-host hacking hacktro vmware workstation
Last synced: 21 Jan 2025
https://github.com/SherlockSec/CVE-2020-0601
A Windows Crypto Exploit
cve cve-2020-0601 exploit windows
Last synced: 23 Oct 2024
https://github.com/whokilleddb/CVE-2019-17662
Exploit for CVE-2019-17662 (ThinVNC 1.0b1)
cve cve-2019-17662 exploit poc thinvnc
Last synced: 23 Oct 2024
https://github.com/mauricelambert/shell-exploit-umbraco
This module implements a shell to exploit a RCE in umbraco CMS.
exploit hackthebox python3 rce rce-exploit remote-code-execution shell umbraco umbraco-cms vulnerability web
Last synced: 14 Jan 2025
https://github.com/mauricelambert/webscriptswebshell
Install a WebShell on hardened and deployed WebScripts (using Apache and mod_wsgi).
apache exploit web-attacks webscripts webshell wsgi
Last synced: 24 Jan 2025
https://github.com/GeorgiiFirsov/CVE-2020-1034
CVE 2020-1034 exploit and presentation
cve cve-2020-1034 education exploit research vulnerability winapi windows
Last synced: 23 Oct 2024
https://github.com/zeyad-azima/cve-2022-22733
Apache ShardingSphere ElasticJob-UI Privilege Escalation & RCE Exploit
apache apache2 exploit java shardingsphere vulnerability
Last synced: 09 Feb 2025
https://github.com/qyfashae/memfd_create_2023_exploit
EDUCATIONAL PURPOSES ONLY! Linux/x64 reverse TCP shell exploit via ELF memory processing
exploit linux-exploits python3 shellcode zero-day
Last synced: 01 Feb 2025
https://github.com/kvba0000/trackmania-xss-payloads
[POC] Repo of XSS payloads you can try when using Trackmania 1's playerpage
exploit game maniaplanet poc proof-of-concept security trackmania trackmania-api trackmania-nations trackmania-united xss xss-vulnerability
Last synced: 13 Nov 2024
https://github.com/gill-singh-a/docker-api-remote-root-shell-exploit
A Simple Python Program that uses Docker Module to communicate with Docker API and gets a Remote Root Shell on the Target Device
Last synced: 07 Feb 2025
https://github.com/ihsandevs/simplewebshell-php
The Simple Web Shell is a lightweight and user-friendly web-based interface for controlling a website using a single PHP file.
ethical-hacking ethical-hacking-tools exploit hacking php remote-code-execution shell webshell webshells
Last synced: 05 Feb 2025
https://github.com/anajuliabit/euler_hack_poc
Euler Incident POC
ethereum evm exploit foundry invariants solidity
Last synced: 01 Feb 2025