This repository hosts PoC exploits for vulnerabilities I've discovered, provided for education and to highlight the importance of system security.
☆19Mar 24, 2023Updated 3 years ago
Alternatives and similar repositories for exploits
Users that are interested in exploits are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆11Sep 7, 2026Updated last month
- Collection of scripts and how-to for hacking embedded devices☆23Feb 16, 2026Updated 7 months ago
- Exploit for CVE-2024-4883☆11Jul 8, 2024Updated 2 years ago
- CVE-2023-1671-POC, based on dnslog platform☆15Apr 26, 2023Updated 3 years ago
- ☆20Jan 21, 2026Updated 8 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- CVE-2021-40865☆14Nov 26, 2021Updated 4 years ago
- CVE-2023-4634☆47Mar 14, 2026Updated 6 months ago
- ☆10Jun 5, 2023Updated 3 years ago
- Writeups, PoCs of the bugs I found while preparing for the Pwn2Own Miami 2023 contest targeting UaGateway from the OPC UA Server category…☆62Aug 5, 2023Updated 3 years ago
- NES emulator written in python☆13Sep 9, 2024Updated 2 years ago
- ACVPatcher patches AndroidManifest and rewrites DEX files inside an APK not touching resources (unlike apktool)☆13Mar 1, 2026Updated 7 months ago
- This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC.☆54Apr 18, 2024Updated 2 years ago
- CVE-2014-10069☆11Jan 7, 2018Updated 8 years ago
- PoC for the CVE-2021-20837 : RCE in MovableType☆18Oct 26, 2021Updated 4 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application desig…☆13Jan 1, 2026Updated 9 months ago
- ☆12Dec 29, 2023Updated 2 years ago
- Trophy list of zero-day vulnerabilities that I discovered☆13May 6, 2024Updated 2 years ago
- DEFCON 30 Car Hacking Village Presentation☆11Sep 11, 2022Updated 4 years ago
- ☆15Mar 22, 2021Updated 5 years ago
- Repo containing all info, scripts, etc. related to CVE-2021-44228☆10Dec 29, 2021Updated 4 years ago
- ☆30Feb 20, 2022Updated 4 years ago
- Documentation for Vilo router vulnerability research☆15Oct 21, 2024Updated last year
- CVE-2023-34362: MOVEit Transfer Unauthenticated RCE☆19Jul 30, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- It's me!! So cute!!!☆16Jul 29, 2026Updated 2 months ago
- This is the ringzer0 writeup of web exploitation catagery. The name is "Word mean something"☆14Dec 8, 2023Updated 2 years ago
- A library and a set of tools for exploiting and communicating with Google's Quick Share devices.☆50Apr 2, 2025Updated last year
- CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability☆12Jul 2, 2018Updated 8 years ago
- Shared library implementations that transform the containing process into a shell when loaded (useful for privilege escalation, argument …☆27Feb 15, 2024Updated 2 years ago
- 📱 RUNIC tamper detection demo - designed to serve as a parallel for understanding more complex tamper detection and integrity systems su…☆18Apr 13, 2024Updated 2 years ago
- apache log4j poc—— base Maven☆13Dec 11, 2021Updated 4 years ago
- Exploit for CVE-2022-27226☆15Mar 19, 2022Updated 4 years ago
- Apache Superset Auth Bypass (CVE-2023-27524)☆10May 9, 2023Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Paramix is a command-line tool for modifying the parameters of a list of URLs from stdin and returns them in stdout.☆17Aug 23, 2024Updated 2 years ago
- Authentication Bypass in GoAnywhere MFT☆65Jan 23, 2024Updated 2 years ago
- WordPress WP_Query SQL Injection POC☆28Mar 11, 2023Updated 3 years ago
- Moxa Nport devices enumerate script☆16Apr 9, 2016Updated 10 years ago
- Exploit for CyberPanel Pre-Auth RCE via Command Injection☆23Nov 1, 2024Updated last year
- Android 14 Beta 1 framework/services source code, reverse engineered from a Pixel 7 Pro (upb1.230309.014)☆15Apr 13, 2023Updated 3 years ago
- ☆11Aug 31, 2023Updated 3 years ago