A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
☆5,142Sep 16, 2026Updated last week
Alternatives and similar repositories for exploitarium
Users that are interested in exploitarium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,618Updated this week
- AdaptixC2 is a highly modular advanced redteam toolkit☆3,638Updated this week
- Decentralized C2 framework built on libp2p☆467Jun 16, 2026Updated 3 months ago
- poc it like it's hot☆1,035Updated this week
- ☆5,013May 10, 2026Updated 4 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- 备份的漏洞库,3月开始我们来维护☆2,223Jul 13, 2026Updated 2 months ago
- Java Vulnerability Exploitation Platform☆2,164Aug 22, 2026Updated last month
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆262May 18, 2026Updated 4 months ago
- The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every …☆7,048Updated this week
- claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md f…☆6,995Sep 19, 2026Updated last week
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,158Updated this week
- HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity to…☆12,154Aug 3, 2026Updated last month
- 一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆4,399Sep 19, 2026Updated last week
- wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain☆784Aug 11, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Another BYOVD process killer. works on all EDR's. fully signed.☆291May 19, 2026Updated 4 months ago
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,597Updated this week
- Open-source AI-powered offensive security harness for automated penetration testing.☆2,884Updated this week
- NGINX RCE exploits☆929Jul 25, 2026Updated 2 months ago
- AI-powered bug bounty hunting toolkit that works with or without subscription.☆5,185Updated this week
- Netlogon and CLDAP vulnerability research with a proof of concept.☆231Jun 2, 2026Updated 3 months ago
- autonomous red teaming platform; multi-agent offensive-security meta-harness☆6,260Sep 8, 2026Updated 2 weeks ago
- Multi-architecture Linux privilege escalation toolkit with 29 pre-built and runtime-compilable exploits. Auto-detects kernel version, fil…☆400Updated this week
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆241Sep 15, 2026Updated last week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code☆4,075Apr 29, 2026Updated 4 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,828Updated this week
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆281Apr 16, 2026Updated 5 months ago
- Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands…☆730Sep 10, 2026Updated 2 weeks ago
- Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full writ…☆1,280Sep 1, 2026Updated 3 weeks ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆31,564Updated this week
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆867May 23, 2026Updated 4 months ago
- Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.☆761May 15, 2026Updated 4 months ago
- Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.☆748May 9, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Helping AI Agent become an awesome practical hacker!☆2,317Sep 13, 2026Updated 2 weeks ago
- A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.☆317Jun 13, 2026Updated 3 months ago
- Activation Context Hijacking Evasion Tool☆309Jun 17, 2026Updated 3 months ago
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,320May 10, 2026Updated 4 months ago
- Fully autonomous AI Agents system capable of performing complex penetration testing tasks☆25,016Updated this week
- 一个用于测试文件上传功能安全性的 Burp Suite 插件。通过 Intruder 模块自动生成各类绕过 payload,覆盖常见的文件上传限制场景。共1000+条payload☆632Dec 24, 2025Updated 9 months ago
- PoC Exploit for the NTLM reflection SMB flaw.☆720Feb 18, 2026Updated 7 months ago