A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
☆4,215Jul 15, 2026Updated last month
Alternatives and similar repositories for exploitarium
Users that are interested in exploitarium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- RoguePlanet Windows Defender Vulnerability☆1,607Jun 9, 2026Updated 2 months ago
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,500Jun 7, 2026Updated 2 months ago
- Decentralized C2 framework built on libp2p☆448Jun 16, 2026Updated 2 months ago
- AdaptixC2 is a highly modular advanced redteam toolkit☆3,521Aug 2, 2026Updated 2 weeks ago
- poc it like it's hot☆896Updated this week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- ☆4,982May 10, 2026Updated 3 months ago
- 备份的漏洞库,3月开始我们来维护☆2,155Jul 13, 2026Updated last month
- Java Vulnerability Exploitation Platform☆2,147Updated this week
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆260May 18, 2026Updated 3 months ago
- The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every …☆5,805Updated this week
- claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md f…☆2,935May 8, 2026Updated 3 months ago
- Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed atta…☆1,861Updated this week
- 一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆4,205Updated this week
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,068Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- GreatXML bitlocker bypass vulnerability☆629Jun 11, 2026Updated 2 months ago
- HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity to…☆11,178Aug 3, 2026Updated 2 weeks ago
- wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain☆745Aug 11, 2026Updated last week
- Another BYOVD process killer. works on all EDR's. fully signed.☆290May 19, 2026Updated 3 months ago
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,579Aug 8, 2026Updated last week
- A AI general-purpose state-space search engine, validated first on autonomous penetration testing.☆2,320Jul 15, 2026Updated last month
- NGINX RCE exploits☆919Jul 25, 2026Updated 3 weeks ago
- AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude…☆4,242Aug 10, 2026Updated last week
- CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)☆209Jun 2, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆214Jul 8, 2026Updated last month
- Multi-architecture Linux privilege escalation toolkit with 24 pre-built and runtime-compilable exploits. Auto-detects kernel version, fil…☆342Jul 7, 2026Updated last month
- Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code☆4,038Apr 29, 2026Updated 3 months ago
- Helping AI Agent become an awesome practical hacker!☆1,795Jun 16, 2026Updated 2 months ago
- autonomous red teaming platform; multi-agent offensive-security meta-harness☆5,605Updated this week
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆863May 23, 2026Updated 2 months ago
- Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.☆759May 15, 2026Updated 3 months ago
- Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full writ…☆1,172Jul 31, 2026Updated 2 weeks ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆278Apr 16, 2026Updated 4 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands…☆699Aug 2, 2026Updated 2 weeks ago
- Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.☆728May 9, 2026Updated 3 months ago
- Activation Context Hijacking Evasion Tool☆306Jun 17, 2026Updated 2 months ago
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,316May 10, 2026Updated 3 months ago
- Windows ProfSvc 0day☆314Jul 14, 2026Updated last month
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆30,587Updated this week
- 一个用于测试文件上传功能安全性的 Burp Suite 插件。通过 Intruder 模块自动生成各类绕过 payload,覆盖常见的文件上传限制场景。共1000+条payload☆627Dec 24, 2025Updated 7 months ago