Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
0day-Rubbish — Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field. | Kitploit
أدوات/GitHubGitHub/exploit-garbage/0day-rubbish
Vulnerability AnalysisExploitationSCADA/ICS SecurityRed TeamingCurated ResourcesAI Security
GitHubexploit-garbage/0day-rubbish

0day-Rubbish

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field.

عرض المستودع
61440منذ 10 أيامتمت المراجعة من قبل Kitploit
الموقع الإلكتروني

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

0day Rubbish

0day vulnerabilities have become rubbish in the AI era.

License: MIT Latest batch Max CVSS PoC Website Watchers Discussions

Last commit

🌐 Official Website: https://0day-rubbish.com/blog


🎯 Why This Exists

Traditional vulnerability disclosure is broken. It's slow, bureaucratic, and ineffective. In the AI era, we can mass-produce 0days at scale—making individual vulnerabilities less valuable but more impactful when disclosed directly.

We believe event-driven security hardening is the most effective approach: only when vendors face real, exploitable threats do they prioritize fixes.

🔄 Our Disclosure Process

Step 1: AI Discovery

Our automated AI systems continuously scan for vulnerabilities across real-world software, identifying potential 0-days through pattern analysis, fuzzing, and intelligent code review.

Step 2: Verification & PoC Development

Each finding undergoes manual validation. We develop working proof-of-concept exploits to confirm exploitability and assess real-world impact.

Step 3: Periodic Public Disclosure

Roughly every two weeks we disclose a new batch of verified, exploitable 0-day vulnerabilities we've discovered and validated:

  • Full technical analysis and root cause
  • Working PoC exploit code
  • Affected versions and systems
  • Impact assessment
  • Recommended mitigations

No delays. No bureaucracy. Just facts.

To all vendors: We hope you can complete fixes before hackers exploit these vulnerabilities.

⚡ Core Principles

  • Real-world impact only: We disclose only vulnerabilities that affect real-world systems with actual user bases
  • No worthless targets: Non-exploitable vulnerabilities or devices with negligible user adoption are excluded—they're rubbish with zero value
  • Speed over protocol: Direct disclosure drives faster action than traditional channels
  • Proof over claims: Every disclosure includes working exploits
  • Impact over quantity: Focus on high-severity, widely-deployed vulnerabilities
  • Transparency: Full technical details, no hidden agendas
  • Non-profit: Driven by passion for security research, not financial gain

🤝 Collaboration

We partner with:

  • Top AI model providers advancing automated security research
  • Security researchers exploring AI-powered discovery

🤖 AI Models Used

Our automated vulnerability discovery leverages cutting-edge large language models from leading AI providers:

  • Anthropic (Claude) - Deep security pattern recognition and reasoning
  • OpenAI - Advanced reasoning and code analysis
  • DeepSeek - Specialized vulnerability detection
  • Z.ai (GLM) - Long-context code analysis
  • Moonshot (Kimi) - Long-context security analysis

📋 Disclosed Vulnerabilities

An AI-driven research process (multi-LLM ensemble: Claude, OpenAI, DeepSeek, GLM, Kimi) discovers 0-days in real-world enterprise software. Every advisory below ships a full root-cause analysis plus a working, reproducible exploit script — no detection-only writeups, no withheld details.

Latest Batch — Batch 9 (12 advisories)

#ProductAffected VersionCVSSClassAdvisory & PoC
1NoMachine Terminal Server (VULN-001)10.0.579.8Pre-auth heap corruption (CWE-787→416), RCE-capableparsePOST heap → corruption
2NoMachine Terminal Server (VULN-002)10.0.579.8Pre-auth stack overflow, return-address controlparsePOST sprintf → RIP control
3StreamSets DataCollector6.4.19.8Default creds + Shell Executor → RootShellDExecutor → Root RCE
4Akana API Platform8.4.299.8Unauth path-normalization bypass → ScriptEngine RCEadmin/../ext → engine.eval RCE
5Puppet Enterprise2025.10.08.8Auth keytool shell injection → Root (CVE-2025-5459 bypass)java_keystore_passwd → Root RCE
6Minuteman UPS NMC1.60.39.8Unauth system_param.csp Cmd Injection → RootWAN config → Root RCE
7Lantronix EDS3000PR (VULN-001)3.2.0.0R28.8Auth FsUnmount Cmd Injection → RootFsUnmount path → Root RCE
8Lantronix EDS3000PR (VULN-002)3.2.0.0R28.8Auth SSL -passin pass:%s Cmd Injection → Rootkeytool pass → Root RCE

Totals: 12 advisories · 10 vendors · 4 unauthenticated · 8 authenticated (deep-chain) · 10 system-level (root/SYSTEM) · all with reproducible PoC.

Earlier batches: Batch #1 · Batch #2 · Batch #3 · Batch #4 · Batch #5 · Batch #6 · Batch #7 · Batch #8


🔁 An Ongoing Series — Weekly Disclosures

This is a continuous disclosure series. Thanks to continuous optimization, the AI-driven discovery pipeline now produces new 0-day findings at a stable daily rate, and we disclose verified batches on a weekly cadence.

  • Latest batch: Batch 9 — 12 advisories (draft); cumulative 90 across 9 batches
  • Next drop: weekly
  • Future scope: expanding beyond enterprise IT into ICS / SCADA, energy, and aerospace systems

If you want to catch the next drop the moment it lands:

Star Watch Blog

⭐ Star to bookmark · 👁 Watch (custom → Releases + Discussions) for new batches · 🌐 Follow the blog for per-advisory updates.


📂 Vulnerability Submission Format

All disclosed vulnerabilities follow a standardized directory structure:

root@kitploit:~
product/
└── <vendor>/
    └── <version>/
        └── <vulnerability_type>/
            ├── exploit/          # Exploit scripts and PoC code
            ├── analysis.md       # Detailed vulnerability analysis
            └── summary.md        # Brief vulnerability overview

Directory Rules

  • product/: Root directory for all vulnerabilities
  • /: Vendor or product name (e.g., apache, cisco, sonicwall)
  • /: Affected version range (e.g., 6.11.0, 12.4.2)
  • <vulnerability_type>/: Classification (e.g., unauth-rce, auth-bypass, deserialization-rce)

Required Files in Each Vulnerability Directory

  1. exploit/: Directory containing working exploit scripts and PoC code
  2. analysis.md: Comprehensive technical analysis including root cause, attack vector, and impact
  3. summary.md: Concise vulnerability overview with affected versions and quick mitigation steps

Example

root@kitploit:~
product/
└── sonicwall/
    └── sma-12.4/
        └── preauth-deserialization-rce/
            ├── exploit/
            │   └── poc.py
            ├── analysis.md
            └── summary.md

Join us in redefining vulnerability disclosure for the AI era.

تنزيل الأداة
9GeoVision GV-TBL4700V1.068.8Auth SNMPv3 net-snmp-config Cmd Injection → RootszAuthKey → Root RCE
10DrayTek Vigor 2960v1.5.1.68.8Auth uploadlangs Cmd Injection → RootcgiEscape gap → Root RCE
11Codoforum5.4.17.2Auth cat_img polyglot upload → www-datapolyglot upload → RCE
12ZesleCP3.1.218.8Auth arbitrary file write → cron → Rootsave-file → cron Root RCE