A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
☆4,873Jul 15, 2026Updated last month
Alternatives and similar repositories for exploitarium
Users that are interested in exploitarium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- RoguePlanet Windows Defender Vulnerability☆1,647Jun 9, 2026Updated 2 months ago
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,544Jun 7, 2026Updated 3 months ago
- AdaptixC2 is a highly modular advanced redteam toolkit☆3,588Updated this week
- Decentralized C2 framework built on libp2p☆456Jun 16, 2026Updated 2 months ago
- poc it like it's hot☆977Aug 25, 2026Updated last week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆4,991May 10, 2026Updated 3 months ago
- 备份的漏洞库,3月开始我们来维护☆2,207Jul 13, 2026Updated last month
- Java Vulnerability Exploitation Platform☆2,159Aug 22, 2026Updated 2 weeks ago
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆262May 18, 2026Updated 3 months ago
- The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every …☆6,419Aug 26, 2026Updated last week
- claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md f…☆3,041Aug 30, 2026Updated last week
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,119Updated this week
- 一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆4,324Sep 1, 2026Updated last week
- HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity to…☆11,601Aug 3, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- GreatXML bitlocker bypass vulnerability☆646Jun 11, 2026Updated 2 months ago
- wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain☆772Aug 11, 2026Updated 3 weeks ago
- Another BYOVD process killer. works on all EDR's. fully signed.☆289May 19, 2026Updated 3 months ago
- Open-source AI-powered offensive security harness for automated penetration testing.☆2,606Updated this week
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,594Aug 30, 2026Updated last week
- A AI general-purpose state-space search engine, validated first on autonomous penetration testing.☆2,634Updated this week
- NGINX RCE exploits☆925Jul 25, 2026Updated last month
- AI-powered bug bounty hunting toolkit that works with or without subscription.☆4,720Updated this week
- Multi-architecture Linux privilege escalation toolkit with 24 pre-built and runtime-compilable exploits. Auto-detects kernel version, fil…☆355Jul 7, 2026Updated 2 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)☆212Jun 2, 2026Updated 3 months ago
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆226Jul 8, 2026Updated last month
- autonomous red teaming platform; multi-agent offensive-security meta-harness☆6,035Updated this week
- Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code☆4,061Apr 29, 2026Updated 4 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆281Apr 16, 2026Updated 4 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,726Updated this week
- Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full writ…☆1,246Sep 1, 2026Updated last week
- Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.☆734May 9, 2026Updated 3 months ago
- Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.☆760May 15, 2026Updated 3 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆867May 23, 2026Updated 3 months ago
- Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands…☆710Aug 2, 2026Updated last month
- Helping AI Agent become an awesome practical hacker!☆2,125Jun 16, 2026Updated 2 months ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆31,058Updated this week
- A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.☆314Jun 13, 2026Updated 2 months ago
- Activation Context Hijacking Evasion Tool☆305Jun 17, 2026Updated 2 months ago
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,321May 10, 2026Updated 3 months ago