☆267Mar 19, 2019Updated 7 years ago
Alternatives and similar repositories for exploits
Users that are interested in exploits are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Some scripts and exploits☆147Jul 9, 2018Updated 8 years ago
- 2 web tasks from ZeroNights HackQuest 2016☆49Mar 24, 2017Updated 9 years ago
- Find known vulnerabilities in WordPress plugins and themes using Burp Suite proxy. WPScan like plugin for Burp.☆183Jul 30, 2019Updated 7 years ago
- A collection of curated Java Deserialization Exploits☆593May 16, 2021Updated 5 years ago
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆54Mar 27, 2017Updated 9 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- a passive scanner based on Mitmproxy and Arachni☆105Aug 17, 2017Updated 8 years ago
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,871Sep 29, 2025Updated 10 months ago
- A Java serializer in JavaScript☆80May 21, 2018Updated 8 years ago
- S2-055的环境,基于rest-show-case改造☆37Dec 7, 2017Updated 8 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆620Mar 4, 2021Updated 5 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,505Oct 12, 2024Updated last year
- Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!☆297Jun 10, 2019Updated 7 years ago
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆100Jul 29, 2019Updated 7 years ago
- Apache Solr Injection Research☆580Jan 28, 2020Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)☆360Jan 11, 2020Updated 6 years ago
- macOS 10.13.3 (17D47) Safari Wasm Exploit☆119Apr 19, 2018Updated 8 years ago
- RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)☆133Jan 19, 2023Updated 3 years ago
- CVE-2019-8449 Exploit for Jira v2.1 - v8.3.4☆68Feb 3, 2020Updated 6 years ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,192Apr 21, 2024Updated 2 years ago
- Apache Karaf XXE Vulnerability (CVE-2018-11788)☆37Jan 6, 2019Updated 7 years ago
- Exploit for Jenkins serialization vulnerability - CVE-2016-0792☆47Aug 2, 2017Updated 9 years ago
- PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM☆51Mar 14, 2018Updated 8 years ago
- Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (…☆316Apr 1, 2019Updated 7 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆121Jan 9, 2018Updated 8 years ago
- Create tar/zip archives that can exploit directory traversal vulnerabilities☆1,055Jun 3, 2021Updated 5 years ago
- ☆231Feb 13, 2019Updated 7 years ago
- A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques☆744May 4, 2019Updated 7 years ago
- PHP Runtime Vulnerability Detection☆479May 25, 2019Updated 7 years ago
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans☆582Sep 7, 2021Updated 4 years ago
- ☆146Jun 20, 2018Updated 8 years ago
- exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts☆166Aug 29, 2023Updated 2 years ago
- List DTDs and generate XXE payloads using those local DTDs.☆663Feb 21, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- CVE-2018-3245-PoC☆172Jul 13, 2021Updated 5 years ago
- CVE-2019-3396 confluence SSTI RCE☆174Oct 1, 2020Updated 5 years ago
- Java RMI enumeration and attack tool.☆747Sep 28, 2017Updated 8 years ago
- CVE-2018-8021 Proof-Of-Concept and Exploit☆104Dec 3, 2018Updated 7 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,404Apr 18, 2023Updated 3 years ago
- The cheat sheet about Java Deserialization vulnerabilities☆3,180May 26, 2023Updated 3 years ago
- Test and exploit for CVE-2017-12542☆90Apr 15, 2018Updated 8 years ago