A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
☆4,133Jul 15, 2026Updated 2 weeks ago
Alternatives and similar repositories for exploitarium
Users that are interested in exploitarium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- RoguePlanet Windows Defender Vulnerability☆1,561Jun 9, 2026Updated last month
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,463Jun 7, 2026Updated last month
- Decentralized C2 framework built on libp2p☆436Jun 16, 2026Updated last month
- AdaptixC2 is a highly modular advanced redteam toolkit☆3,432Updated this week
- poc it like it's hot☆845Jun 30, 2026Updated 3 weeks ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆4,956May 10, 2026Updated 2 months ago
- Java Vulnerability Exploitation Platform☆2,132Apr 29, 2026Updated 3 months ago
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆256May 18, 2026Updated 2 months ago
- The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every …☆5,366Updated this week
- claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md f…☆2,795May 8, 2026Updated 2 months ago
- Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed atta…☆1,314Updated this week
- 一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产 信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆4,080Updated this week
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,024Updated this week
- GreatXML bitlocker bypass vulnerability☆612Jun 11, 2026Updated last month
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity to…☆10,575Apr 27, 2026Updated 3 months ago
- wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain☆655Updated this week
- Another BYOVD process killer. works on all EDR's. fully signed.☆287May 19, 2026Updated 2 months ago
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,564Jul 16, 2026Updated last week
- A AI general-purpose state-space search engine, validated first on autonomous penetration testing.☆2,125Jul 15, 2026Updated 2 weeks ago
- NGINX RCE exploits☆906Updated this week
- AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude…☆4,068Updated this week
- CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)☆207Jun 2, 2026Updated last month
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆203Jul 8, 2026Updated 3 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Multi-architecture Linux privilege escalation toolkit with 24 pre-built and runtime-compilable exploits. Auto-detects kernel version, fil…☆324Jul 7, 2026Updated 3 weeks ago
- Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code☆4,020Apr 29, 2026Updated 3 months ago
- Helping AI Agent become an awesome practical hacker!☆1,501Jun 16, 2026Updated last month
- autonomous red teaming platform; multi-agent offensive-security meta-harness☆5,289Updated this week
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆858May 23, 2026Updated 2 months ago
- Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.☆754May 15, 2026Updated 2 months ago
- An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MI…☆1,021Updated this week
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆276Apr 16, 2026Updated 3 months ago
- Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands…☆613Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.☆706May 9, 2026Updated 2 months ago
- Activation Context Hijacking Evasion Tool☆301Jun 17, 2026Updated last month
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,302May 10, 2026Updated 2 months ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆30,095Updated this week
- 一个用于测试文件上传功能安全性的 Burp Suite 插件。通过 Intruder 模块自动生成各类绕过 payload,覆盖常见的文件上传限制场景。共1000+条payload☆621Dec 24, 2025Updated 7 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,440Updated this week
- SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connecti…☆455Nov 3, 2025Updated 8 months ago