lal0ne / vulnerability
收集、整理、修改互联网上公开的漏洞POC
☆855Updated this week
Alternatives and similar repositories for vulnerability:
Users that are interested in vulnerability are comparing it to the libraries listed below
- WeblogicTool,GUI漏洞利用工具,支持漏洞检测、命令 执行、内存马注入、密码解密等(深信服深蓝实验室天威战队强力驱动)☆1,615Updated last year
- A Swagger API Exploit☆1,217Updated 7 months ago
- xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。☆1,000Updated last year
- Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件☆1,199Updated 6 months ago
- 高危漏洞精准检测与深度利用框架☆1,389Updated 2 years ago
- A flexible scanner☆1,203Updated last month
- 实战沉淀字典☆1,248Updated last month
- A list for Web Security and Code Audit☆996Updated last month
- 面向红队的, 高度可控可拓展的自动化引擎☆1,557Updated this week
- Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描☆1,076Updated last year
- 一款基于BurpSuite的被动式shiro检测插件☆1,699Updated 2 years ago
- MDUT - Multiple Database Utilization Tools☆2,046Updated last year
- 一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.☆1,769Updated this week
- An integrated BurpSuite vulnerability detection plug-in.☆1,180Updated 4 months ago
- POC&EXP仓库、hvv弹药库、Nday、1day☆1,023Updated 2 years ago
- 用于生成各类免杀webshell☆1,126Updated 10 months ago
- (持续更新)对网上出现的各种OA、中间件、CMS等漏洞进行整理,主要包括漏洞介绍、漏洞影响版本以及漏洞POC/EXP等,并且会持续更新。☆489Updated last year
- 记录实战中的各种sql注入绕过姿势☆632Updated 2 years ago
- OA综合利用工具,集合将近20款OA漏洞批量扫描☆1,284Updated last year
- 侦查守卫(ObserverWard)的指纹库☆1,037Updated this week
- 为供应链漏洞扫描设计的快速应急响应工具 [快速应急] [漏洞扫描] [端口扫描] [xray2.0进行时] A fast emergency response tool designed for supply chain vulnerability scanning.☆1,033Updated 5 months ago
- 一款集成高危漏洞exp的实用性工具☆1,181Updated 2 months ago
- 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webs…☆1,367Updated 8 months ago
- Memshell-攻防内存马研究☆683Updated 10 months ago
- Web 版 Java Payload 生成与利用工具,提供 Java 反序列化、Hessian 1/2 反序列化等Payload生成,以及 JNDI、Fake Mysql、JRMPListener 等利用|The web version of Java Payload ge…☆978Updated last week
- OA漏洞利用工具☆1,173Updated 3 months ago
- 攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。☆1,078Updated 3 months ago
- 一款基于BurpSuite的被动式FastJson检测插件☆1,160Updated 2 years ago