Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-security-vul-llm — 本项目通过大模型联动爬虫,检索Github上所有存有有价值漏洞信息与漏洞POC或规则信息的项目,并自动识别项目的目录结构、Readme信息后进行总结分析并分类,所汇总的项目可以帮助安全行业从业者收集漏洞信息、POC信息、规则等。 | Kitploit
Tools/GitHubGitHub/xu-xiang/awesome-security-vul-llm
Vulnerability AnalysisInformation GatheringLearning & EducationCurated ResourcesAI Security
GitHubxu-xiang/awesome-security-vul-llm

awesome-security-vul-llm

本项目通过大模型联动爬虫,检索Github上所有存有有价值漏洞信息与漏洞POC或规则信息的项目,并自动识别项目的目录结构、Readme信息后进行总结分析并分类,所汇总的项目可以帮助安全行业从业者收集漏洞信息、POC信息、规则等。

View Repository
161212 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Awesome Security Vulnerability Project(By LLM)

Project Introduction

This project uses a large model combined with a crawler to retrieve all projects on GitHub that contain valuable vulnerability information, vulnerability POCs, or rule information. It automatically identifies the project's directory structure and Readme information, then summarizes, analyzes, and categorizes them. The aggregated projects can help security industry practitioners collect vulnerability information, POC information, rules, and more.

LLM Analysis Process

  1. Based on GithubGather, use a Token proxy pool to traverse and crawl GitHub project data
  2. Based on aiflows, perform LLM analysis on the crawled data to produce results

Detailed plans will be updated in aiflows, currently not yet complete

Security Learning & Resources

  • zongdeiqianxing/WebSecurityArticles GitHub stars - A collection of Markdown documents containing multiple high-quality web security articles, providing learning resources for Web security
  • zmerry/z-marvel.github.io GitHub stars - Security-related resources and tools, including files and subdirectories from 2017-2019.
  • zj1244/Blog GitHub stars - Learning reference resources for Kubernetes, Docker, security technology articles and tutorials
  • YOURLEGEND/xie-note GitHub stars - Cybersecurity learning resource library, containing learning materials on various topics such as CTF, Web security, intranet penetration, suitable for learning and research in the cybersecurity field.
  • yongsheng220/CTF GitHub stars - Cybersecurity problem bank covering SQL injection, XSS attacks, CWE common vulnerability exploitation, suitable for learning and practicing cybersecurity techniques.
  • yingshang/CybersecurityNote GitHub stars - Security knowledge learning and recording project, covering red team offense and defense, penetration testing, code auditing, and more.
  • Xsw6/JavaSec GitHub stars - Java security study notes, involving ASM, JDBC, Spring, Shiro, and other aspects, with rich practical cases.
  • xqx12/daily-info GitHub stars - Contains technical documents from 2020 to 2023, used for tracking technological development.
  • xitu/gold-miner GitHub stars - A community that translates high-quality internet technology articles, including security-related content.
  • xianshang/1earn GitHub stars - Open source learning resource library, sharing security and operations knowledge
  • wukong-bin/PeiQi-WIKI-POC GitHub stars - PeiQi WiKi-POC library provides knowledge about environment setup, POC, and vulnerability principles, helping people learn various vulnerability-related information.
  • wgpsec/peiqi-wiki GitHub stars - WgpSec POC library is an open-source collection of network vulnerability POCs, including environment setup, POCs, and vulnerability principles. It supports online browsing, offline download, and contribution features.
  • timlzh/webArmory GitHub stars - Web Armory is a CVE knowledge base that can be run via Docker or local compilation, providing convenient vulnerability search functionality.
  • Threekiii/Vulnerability-Wiki GitHub stars - An open-source security knowledge base integrating multiple vulnerability libraries, offering Docker deployment options, suitable for security professionals and technology enthusiasts.
  • TheTh1nk3r/RedTeamLinks GitHub stars - Cybersecurity-related resource links, including offense and defense testing manuals, intranet security documents, learning manual-related resources, checklists and basic security knowledge, product design documents, learning ranges, vulnerability reproduction, open-source vulnerability libraries, etc., suitable for professionals in cybersecurity, red team attacks, and other fields.
  • telekom-security/telekom-security.github.io GitHub stars - Security blog built with Jekyll, providing the latest cybersecurity news and advice
  • SummerSec/BlogPapers GitHub stars - Personal blog website containing articles on Java programming language and security domain knowledge
  • SpeeDr00t/speedr00t.github.com GitHub stars - Provides security-related resources and tools
  • Spacial/awesome-csirt GitHub stars - CSIRT GitHub project collects incident response related resources, including books, links, and a list of security projects. It also includes tools for encoding, encryption, hashing, and obfuscation, as well as search engines for malware analysis, vulnerabilities, and exploits. The project also contains information on incident response frameworks and standards, such as the CERT model and SIM v3 model.
  • Simpsonpt/AppSecEzine GitHub stars - A regularly published open-source cybersecurity news magazine covering various information security issues and the latest hot topics.
  • SherryLiGit/penetration-handbook GitHub stars - Target chain penetration testing guide manual, providing guidance for target chain penetration testing.
  • shengshengli/vulnerability-paper GitHub stars - An open-source project collecting various cybersecurity-related resources, including CISP_PTE, vulnerabilities, bypasses, and evasion content, aiming to provide a security resource library for learning and reference.
  • SexyBeast233/SecBooks GitHub stars - SecBooks is a project containing articles from various we-media accounts, including multiple articles on security, such as vulnerability reproduction, SQL injection, etc., and provides plugin support.
  • ruanyf/weekly GitHub stars - Technology enthusiast weekly, collecting tech content worth sharing each week, including AI, cybersecurity, and other fields. Created by Ruanyf, readers can submit issues to share content. Provides search functionality, with a history of over two years, very valuable.
  • root26/bcak GitHub stars - Baige Wiki is a beta version of the Baize Sec team, containing technical summaries and original articles on cybersecurity, and provides contribution guidelines and document storage format requirements.
  • reidmu/sec-note GitHub stars - Security notes/tools/vulnerability collection, including penetration ideas, vulnerability research, etc.
  • ReAbout/web-sec GitHub stars - Provides explanations of web security, vulnerability understanding, vulnerability exploitation, code auditing, and penetration testing.
  • PeiQi0/PeiQi-WIKI-Book GitHub stars - A knowledge base for cybersecurity practitioners, covering vulnerability research, code auditing, CTF competitions, red-blue confrontation, etc., solving the problems of scattered security information and hard-to-find security materials, helping cybersecurity practitioners build a secure internet.
  • password520/vulnerability-paper GitHub stars - An open-source project of cybersecurity articles, tools, and techniques, including articles related to certification exams, vulnerabilities, bypasses, and range reproduction, providing search functionality and file categorization for learning and reference.
  • NuclearAtk/lcx.cc GitHub stars - Personal blog website, may have XSS attack risks, can be used as learning material and practice target.
  • MrWQ/vulnerability-paper GitHub stars - Open-source project of cybersecurity articles, tools, and techniques, including CISP_PTE, vulnerabilities, range reproduction, etc., with article search functionality
  • lal0ne/HW GitHub stars - Offense and defense manual and vulnerability POCs, providing security defense knowledge and practical experience.
  • kb5000/kb5000.github.io GitHub stars - May contain CSS, JS, images, etc., possibly a personal blog website. Has potential security risks, requires further review.
  • kamranahmedse/developer-roadmap GitHub stars - This is a community-driven developer roadmap, articles, and resources repository, providing learning materials for multiple programming languages and technologies.
  • JnuSimba/MiscSecNotes GitHub stars - Web security, penetration testing study notes and material collection, covering HTTP protocol, cross-site scripting, SQL injection, PHP security, and other topics, including original content and organized understandings of online articles.
  • jas502n/Security_Article GitHub stars - Scrapy crawler project for storing and managing security articles and links
  • hktalent/MyDocs GitHub stars - A report of security vulnerabilities containing multiple CVE IDs, involving multiple open-source website programs and their components such as Joomla, Nginx, WordPress.
  • hhhparty/security GitHub stars - Personal teaching notes, study notes, and security gadgets
  • Haoyunforever/Study GitHub stars - Intranet penetration and range practical experience study notes and related tools to enhance security skills.
  • H3rmesk1t/Security-Learning GitHub stars - Security-Learning is a GitHub project providing learning materials on various security topics, including AISec, BinarySec, DatabaseSec, JavaSec, NodejsSec, PHPSec, Penetration, and PythonSec.
  • goncalor/cve-ark GitHub stars - This project contains data from 1999 to 2024, may involve security risks, need to strengthen data protection measures.
  • github/advisory-database GitHub stars - An open-source security vulnerability database containing security advisories and vulnerability information from various sources, stored in OSV standard format. Users can update or modify information in the database by submitting PRs.
  • friends-of-presta/security-advisories GitHub stars - A platform providing security vulnerability information for PrestaShop modules, including search API and RSS feeds, enhancing the security of the entire ecosystem.
  • ffffffff0x/1earn GitHub stars - Open-source learning resource library, sharing knowledge and practices in various security fields, covering multiple sub-projects and detailed learning paths.
  • euphrat1ca/Security-List GitHub stars - Comprehensive learning and reference resources in application security, wireless proximity, digital forensics, and other fields
  • dream0x01/spear-framework GitHub stars - Spear-framework is a security research platform for collecting and organizing various vulnerabilities and articles, allowing rapid construction of a security knowledge system.
  • cloudsecurityalliance/gsd-database GitHub stars - The Global Security Database (GSD) is an open-source project aimed at creating a community-driven vulnerability database. It includes a vulnerability community guide and two main repositories—database and tools. Data can be accessed via GitHub, API, or web interface.
  • bfengj/CTF GitHub stars - Study notes on penetration testing, JavaScript, Go language, Java security, and some competition problem attachments.
  • batermj/data_sciences_campaign GitHub stars - Data scientist series courses, covering multiple programming languages and database technologies, as well as data analysis practical training.
  • BaizeSec/bylibrary GitHub stars - Baige Wiki is the beta version of Baize Sec team, providing documents and tutorials related to cybersecurity, contributions and learning are welcome.
  • astaxie/build-web-application-with-golang GitHub stars - Open-source tutorial for building web applications in multiple language versions, risk of translation errors, need to verify content accuracy.
  • apachecn/pentesttools-blog-zh GitHub stars - Chinese translation version of PentestTools blog, covering learning materials on multiple security technologies.
  • apachecn/kalilinuxtutorials-zh GitHub stars - Provides security domain knowledge learning resources, including documents, tutorials, and tools.
  • ADummmy/vulhub_Writeup GitHub stars - Web application vulnerability learning and research resources
  • adminlove520/DFYXSec-Wiki-Book GitHub stars - Security knowledge sharing platform built with VuePress and Ant Design, providing quick start guide and local development environment, sharing and disseminating security knowledge.
  • 119dd1bd86728b407fe82fce1f8b9369/catalogue03 GitHub stars - A security project containing directories for 2021, 2022, and 2023, with a README providing information on the project.
  • 0x783kb/Security-operation-book GitHub stars - Security operation manual covering Web, Windows AD, and Linux, suitable for ATT&CK techniques, simulation testing, and detection requirements.# Security Tools & Scripts
  • zhzyker/exphub GitHub stars - Exphub is a security tool project containing multiple exploit scripts, providing exploit support for well-known systems and their versions such as Weblogic, Spring, Struts2, etc. It covers various types of exploits including RCE, Exploit, Command execution, helping security experts conduct penetration testing and vulnerability discovery.
  • zema1/yarx GitHub stars - Yarx is a security tool that automatically generates a Server based on xray's YAML PoC rules and uses xray to scan that Server for vulnerability detection.
  • zan8in/afrog GitHub stars - A security tool for bug bounties, penetration testing, and red teams, offering PoC, GitHub Release, Wiki and other features.
  • yuyudhn/yuyudhn.github.io GitHub stars - This project includes various frontend technologies and security-related configuration files and certificates, usable for security testing and research.
  • ysrc/xunfeng GitHub stars - Xunfeng is a vulnerability rapid emergency and cruising scanning system suitable for enterprise intranets, implementing asset identification and vulnerability detection through a network asset identification engine and a vulnerability detection engine.
  • yaklang/yakit-store GitHub stars - Yak contains multiple submodules such as codec, mitm, module, packet, and portscan, which can be used for implementing network security-related functions.
  • y1ng1996/poc GitHub stars - BugScan: Network security vulnerability scanning and testing tool, implementing automated penetration testing functions.
  • xx-zhang/Medusa GitHub stars - A security toolkit based on secondary development of Medusa, containing multiple vulnerability PoCs and automated penetration tools, supporting Docker deployment.
  • xinyisleep/pocscan GitHub stars - A security toolkit containing a large number of PoC checks, usable for detecting security vulnerabilities in various open-source software and systems. Includes vulnerability scanning scripts for OA systems such as Weaver, Tongda, Zhiyuan, and is continuously updated. Uses the pocsuite library for operation, requires Python environment.
  • xanszZZ/pocsuite3-poc GitHub stars - This project contains various security vulnerabilities and penetration testing tools, usable for detecting and fixing security vulnerabilities in servers, applications, and network devices.
  • x00itachi/msf-ref-collector GitHub stars - Metasploit References Collector, organizes existing references from the Metasploit Framework into CSV format.
  • x-stream/xstream GitHub stars - XStream is a Java to XML deserialization tool, providing high performance and flexibility, supporting custom converters and optional runtime extensions.
  • wonderkun/crawler GitHub stars - Automated article crawling, using Python crawler technology to automatically fetch and organize security-related articles from anquanke.com and xz.aliyun.com, aiming to provide a convenient way to obtain articles.
  • Wker666/Cheetah GitHub stars - Contains various penetration testing tools such as SQL injection, web attacks, binary attacks, etc., suitable for experiments and research in the security field.
  • WingsSec/Meppo GitHub stars - Meppo is a vulnerability detection framework that provides interfaces for FOFA, SHODAN, and Hunter API, and supports single-target and multi-target single PoC or module monitoring.
  • windwant/windwant-service GitHub stars - WindWant Service is an open-source project containing various application examples, including practice and learning of multiple security-related technologies, such as encryption algorithms, consensus algorithms, network programming, message queues, etc.
  • wick2o/osf_db GitHub stars - sf-search.py, used to search for software in the security vulnerability database sfocus.db, supports remote or local vulnerability filtering.
  • wh1t3p1g/MonitorClient GitHub stars - MonitorClient is a C/S-based website source code real-time monitoring and webshell detection/kill tool, featuring file change monitoring and webshell detection, supporting Windows/Linux platforms, with encrypted communication for data security.
  • wagiro/BurpBounty GitHub stars - Burp Bounty is a Burp Suite extension for creating custom scanning rules, providing a user-friendly graphical interface to improve the efficiency of active and passive scanners. It includes preset configuration files, usage instructions, and community-contributed configuration files.
  • w3bd0gs/cocoworker GitHub stars - A self-use web scanner containing about 2k PoCs, planned to port w9scan, and designed user and scan result table structures.
  • w-digital-scanner/w9scan GitHub stars - All-round website vulnerability scanner, containing 1200+ plugins, supporting fingerprint detection, service discovery, and generating HTML format reports.
  • vulsio/msfdb-list GitHub stars - msfdb-list is a tool for automatically collecting vulnerability information and storing it in a parseable format, providing convenient and fast security threat intelligence management.
  • vulsio/goval-dictionary GitHub stars - goval-dictionary is a tool for generating and querying local SQLite format OVAL dictionaries, supporting fetching vulnerability dictionary data from multiple databases and providing a server mode for simple queries.
  • vulsio/gost GitHub stars - gost is a security vulnerability tracker for building a local copy, updating via email or Slack notifications.
  • vulsio/go-msfdb GitHub stars - Search for CVEs in Metasploit-Framework modules, supports local deployment of multiple databases, easy to use.
  • veo/vscan GitHub stars - VScan is an open-source, lightweight, fast, cross-platform website vulnerability scanning tool that helps users quickly detect website security issues. It features fast port scanning, fingerprint detection, login password brute force, PoC detection, and sensitive file detection, supporting multiple input and output types.
  • Tyaoo/picker GitHub stars - Security news crawler and push program based on Github Action, supporting multiple types of security information push.
  • Tyaoo/IoT-Vuls GitHub stars - IoT-Vuls is a security scanning tool for IoT devices, detecting device vulnerabilities and providing fix recommendations.
  • trganda/dockerv GitHub stars - Docker environment supporting vulnerability analysis and development, containing multiple pre-built Docker images and usage instructions, convenient for vulnerability scanning and reproduction.
  • tr0uble-mAker/POC-bomber GitHub stars - A vulnerability detection/exploitation tool for quickly gaining target server privileges using a large number of PoCs/EXPs for high-impact vulnerabilities.
  • topscoder/nuclei-wordfence-cve GitHub stars - Nuclei + Wordfence = CVE Scanning tool. This project provides a large set of updated Nuclei templates for scanning vulnerabilities in WordPress. These templates are based on security reports from Wordfence.com. It is a valuable resource for anyone responsible for managing websites that use WordPress, easy to use, up-to-date, and open-source, so you can modify it to suit your specific needs. If you find this project useful, please consider giving it a star on GitHub. Your support helps make this project better.
  • tiaotiaolong/TTLScan GitHub stars - TTLScan is a plugin-based vulnerability scanner framework supporting multiple input sources and engines, including ip, url, Zoomeye, etc. It can automatically obtain target sets and provides PoC script format specifications. It has implemented detection for RedisUn, RedisGetShell, Struts2 series vulnerabilities, and supports multi-threading and distributed task processing.
  • Threekiii/Awesome-POC GitHub stars - This project provides various open-source security tools and projects, covering a wide range of common security issues and vulnerabilities, including but not limited to permission management, file upload, SQL injection, remote code execution, etc. These tools and projects can help security personnel conduct penetration testing and vulnerability scanning to ensure system security.
  • thetowsif/nuclei-template-fetcher GitHub stars - This project is a repository for collecting Nuclei templates from open-source projects on GitHub, providing templates from 153 source repositories, aiming to share and check templates to avoid false negatives.
  • thanhnx9/nuclei-templates-cutomer GitHub stars - This project, named nuclei-templates-cutomer, includes community templates, full web crawling, Swagger, and other features used for automated testing in the security field.
  • terry494/fengchenzxc.github.io GitHub stars - Network security audit tool, providing vulnerability scanning, risk assessment, and other functions to ensure system security.
  • syadg123/Medusa- GitHub stars - Medusa Scan is an open-source security scanning tool, supporting Bash and Bot versions, capable of website vulnerability scanning, password brute force, etc. Users must comply with relevant laws and regulations and pay attention to protecting personal privacy.
  • SuperKieran/WooyunDrops GitHub stars - Wooyun Drops is a static version of Wooyun Drops, providing full-text search functionality, supporting HTTPS and customizable search engine.
  • Str1am/OAScan GitHub stars - Tool for scanning OA system vulnerabilities, supporting various parameters, including specifying URL for testing, specifying OA system for scanning, and specifying single PoC for scanning.
  • songlh/bigsecurity GitHub stars - VulScan is a vulnerability scanner supporting multiple scan modes, customizable scan rules, helping discover security vulnerabilities in the system.
  • Sharpforce/cybersecurity GitHub stars - MyExpense: A Python open-source tool for simulating user operations and collecting data, including virtual machine IP address display and related articles, book reading notes.
  • shakenetwork/VulApps GitHub stars - VulApps is a Docker image library collecting various vulnerability environments and security tool environments, convenient for security testing and learning. Includes various web applications (e.g., Struts2, WordPress), network devices (e.g., Cisco, Nginx), and security tools (e.g., Xunfeng, Ant). Each environment has a corresponding tag, users can easily pull and run via docker commands.
  • shadow1ng/fscan GitHub stars - fscan is an intranet comprehensive scanning tool for intranet penetration testing, including host discovery, port scanning, service brute force, etc.
  • sepehrdaddev/zap-scripts GitHub stars - ZAP plugins, active and passive scanning scripts for discovering vulnerabilities and secrets.
  • selinuxG/Golin GitHub stars - Features include host discovery, vulnerability scanning, subdomain scanning, asset scanning, various service database brute force, and PoC scanning. Supports web mode preview, weak password/unauthorized access scanning, etc.
  • seifreed/VirusShare GitHub stars - VirusShare contains static data extracted from malware repositories for academic use.
  • SecWiki/CMS-Hunter GitHub stars - CMS-Hunter is a tool for vulnerability scanning and remediation of various CMS systems, helping users promptly discover and fix security risks in their systems.
  • scipag/AttackToolKit GitHub stars - ATK is a customizable security scanning and exploitation tool for detecting specific vulnerabilities. It combines a security scanner (e.g., Nessus) and an exploitation framework (e.g., Metasploit), works without interaction, and allows users to customize plugins, checks, enumeration, and reporting according to their needs.
  • saucer-man/saucerframe GitHub stars - Batch PoC detection framework, supporting multi-threaded concurrency/co-routine requests, multiple target specification methods, multiple API target acquisition, and extensible functions.
  • sari3l/Poc-Monitor GitHub stars - Used to monitor CVE vulnerability information updates and provide notification features. Users can query files to get the latest vulnerability information, or set notification rules to automatically send notifications when new vulnerability information appears.
  • ryanmrestivo/red-team GitHub stars - Provides various tools and information used by security professionals, including notes on red team materials, testing techniques, and network scanning tools. Also includes descriptions of TCP/IP socket programming APIs and examples of how to use them to transfer files and establish remote shells across different networks. Additionally contains information on PowerShell and its application in network penetration testing. Overall, this project is a comprehensive resource for anyone interested in network security and penetration testing.
  • Ricky-Wilson/CodeBase GitHub stars - CodeArchive provides code examples in multiple programming languages to help users understand and master related technologies. Some examples also involve solutions to security-related issues, offering practicality and security.
  • rapid7/metasploit-framework GitHub stars - Metasploit is an open-source penetration testing tool, providing detailed documentation and tutorials to help users install and use it.
  • randomtable/ChimeraOS GitHub stars - This project provides a distributed IRC service aimed at private communication. It leverages Docker and the Tor network model to scale hidden services, building a scalable and highly available communication network. The project has strong security features, such as using distributed hidden services to protect user privacy, as well as scalability and high availability.
  • rabbitmask/AssetsHunter GitHub stars - Asset hunting framework supporting multiple information collection and data deduplication features.
  • r00tSe7en/gitbook GitHub stars - Online tool collection providing various information gathering and search functions, such as DNS, search engines, subdomain/IP/旁站C段, email collection, etc.
  • qsdj/cncs-armory-ktrimisu GitHub stars - CScan is a Python-based security automated scanning framework supporting multiple strategies and vulnerability detection, and includes automatic formatting and static analysis tools.
  • qingchenhh/qc_poc GitHub stars - PoC collection, including organized days from HVV 2023, some README, and miscellaneous PoCs, mainly used for security technology verification and sharing.
  • qazbnm456/awesome-cve-poc GitHub stars - Collects common vulnerability PoCs with detailed descriptions.
  • projectdiscovery/nuclei-templates GitHub stars - Nuclei Templates is a community-maintained collection of templates for the nuclei engine to identify security vulnerabilities in applications. This repository contains various templates provided by the team and contributed by the community, organized by directory and severity level. The project aims to provide a comprehensive resource for security professionals to quickly and easily scan for vulnerabilities in systems.
  • praetorian-inc/purple-team-attack-automation GitHub stars - Purple Team ATT&CK Automation is a Metasploit Framework project that automates MITRE ATT&CK TTPs as post-exploitation modules, enabling blue teams to simulate attacker behavior and test their detection and response capabilities. The project includes over 100 automated TTPs and can emulate the functionality of other tools such as in-memory .NET execution. The project is open-source and available on GitHub. To use it, users must have Docker installed and can follow the instructions in the project README.
  • pokerfacett/freebuf_scrapy GitHub stars - Crawler program for collecting articles and their keywords from freebuf, facilitating security research and learning.
  • pimps/CVE-2017-1000486 GitHub stars - Security tool exploiting padding oracle vulnerabilities.
  • pedrib/PoC GitHub stars - Security research repository created by Pedro Ribeiro, containing research notes, exploit code, and vulnerability information, released under the GPLv3 license.
  • pdelteil/BugBountyReportTemplates GitHub stars - Provides various vulnerability report templates suitable for security researchers and developers.
  • Patrowl/PatrowlHearsData GitHub stars - PatrowlHearsData is an open-source vulnerability intelligence platform that collects and provides CVE, CPE, CWE, and Exploit reference data, offering a public repository of raw data and scraping scripts.
  • patrickmpalmer/exploit-prediction-calculator GitHub stars - exploit-prediction-calculator is a security tool for predicting and preventing potential exploit usage. It includes code in the UI, data_gathering, intelligence_engine, and user_interface directories, enabling real-time monitoring and warning of security threats and providing corresponding defense measures.
  • ParrotSec-CN/ParrotSecCN_Community_QQbot GitHub stars - ParrotSecCN_Community_QQbot is a QQ bot that provides functions such as searching forums, displaying vulnerabilities, system vulnerability scanning, and email sending.
  • paralax/awesome-honeypots GitHub stars - Awesome Honeypots is a GitHub repository collecting various open-source network and application honeypot tools, including web honeypots, database honeypots, etc., providing detailed usage guides and installation instructions, with PoC collection capabilities.
  • OpenWireSec/metasploit GitHub stars - Metasploit is a powerful network security tool for penetration testing and exploit development, released under the BSD license, providing detailed documentation and tutorials, and supporting user-customized extensions.
  • opensec-cn/kunpeng GitHub stars - Kunpeng is a security detection framework that can detect various types of security vulnerabilities, including databases, middleware, web components, CMS, etc. It provides multi-platform support, solves the wheel problem, and reduces wheel consumption. All collected vulnerabilities have been verified via PoC and theoretical judgment, without launching actual attacks.
  • olbat/nvdcve GitHub stars - This project provides JSON files for NVD and CVE® dictionaries, and can explore their modification history via Git. JSON files are generated and updated daily by NVD's JSON feed and Travis CI. Data can be accessed via https://olbat.github.io/nvdcve/CVE-YYYY-NNNN.json.
  • ntop/ntopng GitHub stars - ntopng is a network traffic monitoring application providing a web interface and improvements in performance, ease of use, and features, supporting multiple platforms with source code and precompiled packages available.
  • njcx/pocsuite_poc_collect GitHub stars - pocsuite_poc_collect is a tool that uses the pocsuite framework to collect PoC tools for vulnerability testing in the security field.
  • neuvector/vul-source GitHub stars - ubuntu-cve-tracker.commit is a security tool for tracking Ubuntu system vulnerabilities, providing related files and subdirectories.
  • nbxiglk0/Note GitHub stars - Network security audit tool, supporting vulnerability scanning, risk assessment, and other functions to ensure system security.
  • NanJishen/nanjishen.github.io GitHub stars - This project provides various security-related tools and scripts, including vulnerability scanning, penetration testing, security assessment, etc.
  • Nan3r/myspider GitHub stars - Contains spiders subproject, using scrapy and requests_html to crawl online jokes and news.
  • mrojz/rconfig-exploit GitHub stars - Contains exploit code and related documentation for SQL injection attacks and vulnerability detection.
  • Mr-xn/Penetration_Testing_POC GitHub stars - A collection of various penetration testing tools, scripts, and articles.
  • Mr-xn/BurpSuite-collections GitHub stars - Burp Suite plugin collection, including localized versions and automatic update scripts.
  • merlinepedra/OA-EXPTOOL GitHub stars - A Python tool for vulnerability detection in OA products, with a command-line interface and report generation, capable of detecting multiple vulnerabilities and supporting updates.
  • mageni/mageni GitHub stars - Mageni is an open-source vulnerability and attack surface management platform that helps organizations discover, assess, prioritize, and remediate vulnerabilities in their assets and services. It provides a faster, more enjoyable, and leaner vulnerability management experience, and supports various industries such as PCI DSS, NIST, HIPAA, ISO, NERC, FISMA, and NIS, meeting compliance requirements.
  • luck-ying/Library-POC GitHub stars - This project contains various open-source security-related projects, including but not limited to code audit, vulnerability discovery, security tool development, and vulnerability research.
  • Lucifer1993/AngelSword GitHub stars - AngelSword is a CMS vulnerability detection framework written in Python, helping security engineers quickly find vulnerabilities.
  • lovechinacoco/https-github.com-mai-lang-chai-Middleware-Vulnerability-detection GitHub stars - A tool for detecting vulnerabilities in various middleware products, supporting popular middleware such as Apache, Joomla, Harbor, Kibana, Jboss, Seeyon, ThinkCMF, PHP-FPM, and providing corresponding vulnerability scanning and remediation methods.
  • LittleBear4/OA-EXPTOOL GitHub stars - OA-EXPTOOL is an exploit framework for detecting common high-risk vulnerabilities in enterprise application systems. It uses YAML files for vulnerability verification and has an interactive command-line interface. It also supports batch scanning, error handling, result output, etc.
  • likescam/AttackDetection GitHub stars - Suricata PT Open Ruleset, containing a series of Suricata rules for detecting network security vulnerabilities and malicious activities, also provides PoC exploits and sample traffic data. These rules are optimized for TLS communication and use a custom SID range (10000000-10999999). The project is licensed under Apache 2.0.
  • LHXHL/QiuPoc GitHub stars - QiuPoc is an automated vulnerability detection tool written in Go, containing multiple known PoCs, supporting detection of single or batch targets.
  • larsbijl/trending_archive GitHub stars - This project contains daily GitHub trending information in multiple languages, serving as a reference for security personnel to understand the latest technology trends.
  • lanjelot/kb GitHub stars - Contains various types of penetration testing tools and resources covering networks, operating systems, databases, web applications, etc., suitable for security researchers and penetration testers.
  • kylekirkby/Python-Exploit-Search-Tool GitHub stars - A Python project for searching using Offensive Security's Exploit-db and Shodan's Exploit DB API. Includes display.py, exploitdb.py, main.py, and shodandb.py files, as well as directories for different platforms. A powerful tool for security professionals seeking system vulnerabilities.
  • KTZgraph/sarenka GitHub stars - Sarenka is an open-source intelligence tool for collecting and understanding attack surfaces. It can obtain information about internet-connected devices from search engines and provide Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE) databases, and a mapping from CVE to CWE. It also offers simple tools such as a hash calculator, Shannon entropy calculator, and basic port scanner.
  • jorhelp/Ingram GitHub stars - A scanning framework targeting network camera vulnerabilities, integrating multiple brand devices, supporting custom targets and ports, usable for security testing.
  • jaeles-project/jaeles-signatures GitHub stars - Plugin repository for the open-source vulnerability scanner Jaeles, containing various signature files for different targets, used to detect common vulnerabilities and misconfigurations.
  • izj007/wechat GitHub stars - WeChat favorites article list, used to store and display articles bookmarked by users in WeChat.
  • Invicti-Security/netsparker-custom-security-checks GitHub stars - Provides custom security checks for Invicti Standard's vulnerability detection functionality. These checks are written in JavaScript and can be used to identify potential vulnerabilities in HTTP responses. The project includes a directory structure and README file explaining how to use and contribute.
  • ihebski/XSS-Payloads GitHub stars - Contains various standard and latest XSS attack vector payload code examples.
  • iamHuFei/HVVault GitHub stars - HVVault is a security tool for detecting and exploiting some network vulnerabilities that emerged in 2023, integrating multiple PoC libraries based on Nuclei scanning templates.
  • HorseLuke/drafts GitHub stars - Tool for storing and sharing drafts, no special security features.
  • hi-KK/VulDB_Spider GitHub stars - A vulnerability database crawler tool based on the PySpider crawler framework, supporting crawling of domestic and international vulnerability databases such as NVD, CNVD, and CNNVD, and providing detailed vulnerability information display and query functions, making it convenient for users to obtain and handle security threats in a timely manner.
  • HatBoy/Pcap-Analyzer GitHub stars - A packet analysis tool developed in Python, supporting analysis of multiple protocols, including but not limited to network traffic, basic packet information, protocol analysis, security risk analysis, and extraction of sensitive data and specific protocol transfer files from packets. It also provides a function to plot the latitude and longitude map of accessing IPs. Users can operate via a simple and easy-to-use graphical interface, and improve the accuracy of analysis results by modifying configuration files.
  • hary654321/webscan GitHub stars - Webscan is a web scanning tool for security purposes, written in Go and using LevelDB. It includes features like directory traversal and log data management.
  • hahwul/mad-metasploit GitHub stars - Mad Metasploit is a collection of custom Metasploit modules, plugins, and resource scripts for various purposes such as auditing, exploitation, and resource scripts. It also features an archive function for easy updating and deleting of collected content. The project is available on Github and can be installed via multiple methods, including manual installation and integration into the Metasploit framework. Donations can be made via PayPal and Buy Me a Coffee.
  • GhostTroops/scan4all GitHub stars - Free cross-platform Web network ncat reverse shell tool, supporting multiple protocols and password brute force, fast scanning and smart password brute force features, including 23 different password brute force methods and 15000+ PoC detection capabilities.
  • fozavci/metasploit-framework-with-viproy GitHub stars - Metasploit security framework containing multiple modules and plugins, usable for penetration testing and exploit development.
  • fofapro/vulfocus GitHub stars - Vulfocus is a vulnerability integration platform that packs vulnerability environment Docker images, ready to use out of the box.
  • ExpLangcn/NucleiTP GitHub stars - NucleiTP is a full-network monitoring tool that performs automated security testing and risk assessment on network security through real-time updated PoCs, supporting multiple risk level classification storage.
  • ExpLangcn/HwToolslibrary GitHub stars - Contains a plugin directory and three files, providing vulnerability detection example codes, supporting AI-generated PoC plugins. Network security tool library.
  • Esonhugh/Nuclei-Template-Backup GitHub stars - Nuclei Templates is a community-curated list of templates for the nuclei engine to find security vulnerabilities in applications. It includes various templates provided by the team and contributed by the community. The project has an active community on Discord and Twitter, and welcomes contributions via pull requests or Github issues.
  • Ershu1/2023_Hvv GitHub stars - Collection of information related to HVV confrontation, including scanners, penetration testing tools, and scripts.
  • edoardottt/missing-cve-nuclei-templates GitHub stars - Weekly updated data on CVEs missing from the official nuclei templates repository. Sorted by vulnerability type and year, with counts and data links for each category. Helps security professionals build custom templates to handle missing CVEs and improve overall product security through penetration testing and vulnerability assessment.
  • ed-red/redmc_custom_templates_nuclei GitHub stars - A set of custom templates developed by the redmc team based on the Nuclei tool, used to discover vulnerabilities and misconfigurations in cloud environments.
  • echohun/tools GitHub stars - Security testing tool collection, including port scanning, subdomain collection, fingerprint collection, vulnerability scanning, and brute force.
  • e-m-b-a/emba GitHub stars - EMBA is an open-source security scanner that performs static and dynamic analysis on firmware of embedded devices, identifying weaknesses and vulnerabilities. It generates web reports for further analysis and has system emulation and AI-assisted analysis options.
  • DefectDojo/django-DefectDojo GitHub stars - Django DefectDojo is an open-source security management tool that coordinates security testing, vulnerability tracking, deduplication, remediation, and reporting. Provides DevSecOps, ASPM (Application Security Posture Management), and vulnerability management solutions. The project includes executable files, directory structure, and README information.
  • danielmiessler/SecLists GitHub stars - SecLists collects various types of security testing lists, such as usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, etc., useful for security assessments.
  • danielgottt/malware-detection-analytics GitHub stars - This project, named detection-rules/analytics, provides some rules and analytics, including tools like YARA, Suricata, Sigma, Osquery, and LOLBAS, aimed at detecting network security threats.
  • d3ckx1/Fvuln GitHub stars - Automated security tool that probes alive IPs, open ports, web services, scans web vulnerabilities, performs brute force, and generates reports.
  • cws6/POC-python GitHub stars - Uses the pocsuite framework for vulnerability detection, including security test scripts for remote code execution and SQL injection in multiple CMS systems and web servers.
  • CVEDB/Poc-Git GitHub stars - Provides publicly available exploit codes from the past two decades, supports browsing and searching for specific products or versions, and offers functionality to create searchable HTML tables.
  • coffee727/VE GitHub stars - VulApps is a Docker image library collecting various vulnerability environments and security tool environments, convenient for security testing and learning.
  • CLincat/vulcat GitHub stars - Vulcat is an open-source web application security scanning tool that can detect various web vulnerabilities and provide detailed reports and solutions.
  • Ciyfly/woodpecker GitHub stars - Woodpecker is a security tool implemented in Go, supporting PoC scanning validators for Xray nuclei YAML and Go code. Woodpecker has a web backend mode and command-line mode, and supports progress bar data, yaml/go poc import to db scripts, etc.
  • chaitin/xray_blog GitHub stars - Provides article categorization, tags, and archiving functions, with good security.
  • chaitin/xray GitHub stars - xray is a powerful security assessment tool that provides multiple plugins for detecting common network security issues, such as XSS, SQL injection, command/code injection, weak passwords, etc. It also supports custom PoCs and includes some commonly used PoCs for easy user extension. xray's detection modules continuously add new plugins covering more vulnerability types. In addition to basic web scanning, xray supports advanced features like file upload and weak password detection. Using xray can quickly and efficiently discover potential security risks, making it very practical for network administrators and security engineers.
  • chainreactors/picker GitHub stars - Open-source tool that transforms GitHub repositories into private communities, supporting authentication and permission control.
  • CERT-Polska/Artemis GitHub stars - Artemis is a modular network reconnaissance tool and vulnerability scanner built on Karton, used for checking website security and generating easy-to-read security improvement messages. Initiated by the KN Cyber science club at Warsaw University of Technology and maintained by CERT Polska.
  • cckuailong/reapoc GitHub stars - Reapoc is an open-source security vulnerability range repository containing multiple PoCs and vulnerability targets, supporting frameworks like pocsploit, Nuclei, xray, pocsuite3, goby, and provides yearly vulnerability count statistics and directory lists for each year.
  • capiton0/templates GitHub stars - An automated penetration testing template project based on nuclei, including fingerprint recognition, vulnerability scanning, asset collection, and provides detailed usage documentation and tutorials.
  • C0reL0ader/EaST GitHub stars - EaST Framework is an open-source penetration testing framework containing multiple network attack tools and modules, characterized by high security, usability, extensibility, and cross-platform support.
  • c0py7hat/POC-EXP GitHub stars - POC-EXP is a collection of security tools containing various exploit codes and tools, suitable for security research and testing.
  • brianwrf/hackUtils GitHub stars - Tool kit for penetration testing and network security research based on Beautiful Soup, including multiple remote code execution exploit modules like Joomla, Apache Shiro, etc.
  • barrracud4/image-upload-exploits GitHub stars - Image Upload Exploits is a Github project containing old image exploits for known vulnerabilities in image processors.
  • baidu-security/app-env-docker GitHub stars - Application test environment built on Docker, can verify protection effects and supplement vulnerability descriptions, supports web vulnerability scanning and OpenRASP vulnerability testing, automatically forwards requests via socks5 proxy, more secure than modifying DNS.
  • baboshute/baboshute.github.io GitHub stars - Knowledge base integrating multiple vulnerability databases, providing vulnerabilities in OA, CMS, development frameworks, etc., supports Docker deployment.
  • Arvinthksrct/alltemplate GitHub stars - 3CX Phone Management Console is a tool for managing and configuring 3CX business phone systems, providing a visual interface, user management, grouping, and permission settings, while also featuring authentication and authorization mechanisms to enhance system security.
  • aquasecuritySAglobalSSCS/insecure-bank GitHub stars - Web application for testing security vulnerabilities, running on Tomcat or Docker, with hardcoded login credentials.
  • aquasecurity/vuln-list-reserve GitHub stars - Vuln-list-reserve is a backup repository for storing vulnerability lists when the vuln-list website is inaccessible.
  • apache/solr-site GitHub stars - This project is the source code repository for the Apache Solr website, using Markdown syntax and the Pelican tool to generate static web pages, and automatically building and previewing via ASF Buildbot. Editing is recommended via local build and preview, using ./build.sh -l for live preview. Python 3.5+ is recommended and dependencies should be installed using pip. To manually install Pelican, use pip install -r requirements.txt. It is recommended to create a virtual Python environment to avoid conflicts.
  • anasbousselham/fortiscan GitHub stars - Fortiscan is an exploitation tool targeting FortiGate SSL-VPN vulnerabilities, can be used to check if a device is vulnerable and supports obtaining device plaintext credentials.
  • AmyangXYZ/AssassinGo GitHub stars - AssassinGo is an extensible information gathering and vulnerability scanning framework supporting WebSocket Web GUI, with multiple features such as getting security headers, bypassing CloudFlare, detecting CMS versions, honeypot detection, port scanning, traceroute and marking subdomains on Google Maps, directory scanning and site map, Whois lookup, crawling parameterized URLs, basic SQLi check, basic XSS check, intruder, SSH Bruter, Google-Hacking with Headless-Chrome, friendly PoC interface and WebSocket Web GUI. It is licensed under MIT.
  • amcai/myscan GitHub stars - Python3-based security tool that uses Burpsuite and Redis to build a passive scanner, capable of detecting various security vulnerabilities in networks.
  • ambionics/phpggc GitHub stars - PHPGGC is a library of unserialize() payloads along with tools to generate them from the command line or programmatically. It can be considered as a PHP equivalent of ysoserial for PHP.
  • Alfresco/SearchServices GitHub stars - Alfresco Search Services source code repository, providing search capabilities, supporting Solr core functionality, usable for Alfresco Content Services.
  • al0ne/suricata-rules GitHub stars - Suricata-rules is a GitHub project for collecting and sharing high-quality Suricata IDS rules, aiming to provide network security protection.
  • adminlove520/Nuclei_Online GitHub stars - An open-source tool for network security scanning, supporting online execution and local templates, providing rich vulnerability detection functions.
  • adampielak/nuclei-templates GitHub stars - Security-related YAML files on GitHub, can configure tools and systems to enhance security.
  • 78778443/QingScan GitHub stars - QingScan is a security scanning tool that can automatically invoke various scanners to scan targets and display results centrally, convenient for user management and analysis.
  • 2lambda123/AttackDetection GitHub stars - Suricata PT Open Ruleset is a project containing network-layer attack and malicious activity detection rules, PoC exploits, and sample files. It includes a portion of rules for detecting TLS communication, requiring parameter settings in the suricata.yaml configuration file to activate. The project is maintained by the Attack Detection Team, who are dedicated to finding new vulnerabilities and 0-days and creating PoC exploits to understand how these vulnerabilities work and how related attacks can be detected at the network layer.
  • 20142995/pocsuite3 GitHub stars - Open-source security toolkit containing a large number of Python scripts for collecting and testing network security-related vulnerabilities, supporting multiple common vulnerability types such as SQL injection, remote code execution, file upload, etc.
  • 0x727/FingerprintHub GitHub stars - Security fingerprint library, containing fingerprint information for Apache Shiro components, supports custom requests, automatic updating of fingerprint library.# Vulnerability Discovery and Testing
  • zeroc00I/AllVideoPocsFromHackerOne GitHub stars - Collects hacker zero-day reports and downloads all JSON files for searching, aiming to classify vulnerabilities by technique.
  • wy876/POC GitHub stars - Vulnerability collection, 2023 vulnerability information, providing EXP and POC.
  • wwl012345/Vuln-List GitHub stars - Vuln-List is a project that collects vulnerabilities of various common frameworks, providing detailed vulnerability descriptions, affected versions, POC/EXP, etc., making it easy for users to quickly find and exploit vulnerabilities.
  • wooluo/POC GitHub stars - A security research project that collects known vulnerability POCs, providing multiple POCs and vulnerability testing tools, along with related references and online verification services.
  • Viralmaniar/BigBountyRecon GitHub stars - Uses Google dorks and open-source tools for initial reconnaissance of target organizations, applying 58 techniques to gather information and estimate the target's security maturity level.
  • Veraxy00/SkywalkingRCE-vul GitHub stars - This project is a reproduction and exploitation example of the Apache SkyWalking remote code execution vulnerability, which has an encoding issue that could lead to arbitrary code execution.
  • v1cker/kekescan GitHub stars - kekescan is a comprehensive security scanning tool that includes multiple modules for web, bug, and file scanning, designed to discover vulnerabilities and improve system security.
  • uboolean/exploitdb GitHub stars - The official Git repository of the Exploit Database, containing the latest vulnerabilities and exploit code, and providing the SearchSploit tool for searching. Additionally, it includes executable file lists and other resources.
  • trickest/cve GitHub stars - CVE PoC provides all publicly available vulnerability proof-of-concept examples from the past nearly 20 years, with automatic updates and filtering capabilities.
  • TobinShields/qdPM9.1_Exploit GitHub stars - Exploits vulnerability CVE-2020-7246 by uploading a user photo with malicious code to achieve remote code execution (RCE).
  • threedr3am/learnjavabug GitHub stars - This project contains multiple submodules that record and analyze vulnerabilities in common frameworks or libraries such as Fastjson, Jackson, Dubbo, Apache CXF, Spring, Tomcat, Apache POI, etc., and provides example code for exploiting these vulnerabilities for various attack methods including RCE, SSRF, DoS, information leakage, etc.
  • TheMirkin/CVE-List-Public-Exploits GitHub stars - Contains CVE list and exploits folder, providing exploit tools for various public CVE vulnerabilities.
  • tenable/poc GitHub stars - Tenable's vulnerability exploit code repository, containing exploit code for multiple vendor products, usable for vulnerability discovery and testing.
  • STMCyber/CVEs GitHub stars - STM Cyber Proof-of-Concept exploits library, a collection of PoC exploits for publicly disclosed vulnerabilities in various software products.
  • SleepingBag945/dddd GitHub stars - Supports multiple input formats, active/passive fingerprint recognition, supply chain vulnerability detection tool.
  • SkyBelll/CVE-PoC GitHub stars - Provides publicly available proof-of-concept code for vulnerabilities from the past nearly four years, sorted by CVSS score. Users can search for specific products and versions to find related vulnerability information and generate easy-to-read markdown files. Additionally, the project offers automated processes to filter out false results and generate GitHub badges.
  • shadowsock5/Poc GitHub stars - Information on various open-source software and their exploit methods, covering multiple fields, suitable for security researchers and penetration testers.
  • secrove/Vulnerabilities GitHub stars - This project contains multiple exploit codes and related information for Oracle Weblogic and Spring, including but not limited to CVE-2016-0572, CVE-2017-10137, etc., with certain security research value.
  • s7ck-Team/exploit-db GitHub stars - Exploit-db is a security project containing various exploit tools, aiming to provide the latest security threat information and solutions.
  • RhinoSecurityLabs/CVEs GitHub stars - CVE vulnerability PoC attack script library, covering various types of vulnerabilities from local privilege escalation to remote code execution.
  • redteam-project/exploit-curation GitHub stars - LEM-curation collects and manages the exploit database used by the LEM tool, for vulnerability discovery and testing.
  • rbowes-r7/refreshing-soap-exploit GitHub stars - This project is a PoC tool for the F5 Big-IP security vulnerability CVE-2022-41622, which causes cross-site request forgery in the SOAP interface, allowing an attacker to execute any supported SOAP request using an authenticated user's session. The project provides a script for generating malicious XML templates and examples of important SOAP WSDL files.
  • PortSwigger/BChecks GitHub stars - Provides Burp Suite Professional users with multiple types of vulnerability detection plugins, including blind SSRF, exposed git directory, leaked AWS tokens, log4Shell, server-side prototype pollution, suspicious input transformation, etc., along with examples and other useful tools.
  • Phuong39/2022-HW-POC GitHub stars - Collects POC codes for various open-source tools and libraries, for security research and evaluation. Supports various attack methods such as SQL injection, remote code execution, etc.
  • p0dalirius/CVE-2022-21907-http.sys GitHub stars - This project contains code to demonstrate a security vulnerability in the Windows OS HTTP.sys driver. This vulnerability allows an attacker to execute arbitrary code on a Windows server after sending a specific type of HTTP request. The project includes executables and other resources related to the vulnerability.
  • Ostorlab/known_exploited_vulnerbilities_detectors GitHub stars - A security tool that detects known exploited vulnerabilities, supports scanning IP addresses, domain names, and links, can work with tools like subfinder or dnsx to scan all subdomains, and has implemented detection functions for some CVE IDs.
  • ohnonoyesyes/CVE-2023-29084 GitHub stars - Command injection vulnerability PoC for ManageEngine ADManager Plus.
  • NoorahSmith/Exploit-DB-offsec GitHub stars - The official Git repository of the Exploit Database, containing the latest vulnerabilities and exploit code. Provides the SearchSploit tool for searching.
  • noname1007/vulhub GitHub stars - Vulhub is an open-source collection of pre-built vulnerable Docker environments, usable for vulnerability discovery and testing.
  • nomi-sec/PoC-in-GitHub GitHub stars - This project is a collection of PoCs (Proof of Concepts), containing various vulnerability and attack code examples, including but not limited to CVE-2023-0045, CVE-2023-0099, CVE-2023-0156, CVE-2023-0157, and CVE-2023-0159, covering various security issues such as memory leaks, privilege escalation, file inclusion, and XSS attacks.
  • MzzdToT/HAC_Bored_Writing GitHub stars - This project contains various batch-scanning PoCs and EXPs for unauthorized access, RCE, file upload, SQL injection, information disclosure vulnerabilities. Additionally, it provides tracking updates for the latest PoCs and EXPs.
  • migueltarga/CVE-2020-9380 GitHub stars - PoC IPTV Smarters Exploit, exploiting a vulnerability in the file includes/ajax-control.php to achieve remote code execution, with Python script and screenshot verification.
  • LongWayHomie/CVE-2021-43936 GitHub stars - This project named 'CVE-2021-43936' contains exploit code and test results, can execute code remotely, posing a serious security risk. Use with caution.
  • light-Life/BUG-Pocket GitHub stars - Small vulnerability library, including FOFA syntax and batch scripts, for learning purposes only, strictly prohibited for illegal use.
  • langsasec/hw2023-bigbang GitHub stars - This project contains multiple subdirectories, can be used to research unauthorized access in WeCom (WeChat Work) and vulnerabilities in products and services of multiple well-known security vendors.
  • lal0ne/vulnerability GitHub stars - A tool for collecting, organizing, and modifying publicly available vulnerability PoCs from the internet, containing a large amount of product fingerprint information and search engine results.
  • KiritoLoveAsuna/Exploits GitHub stars - Contains self-written and collected various exploit codes, covering N-day and 0-day vulnerabilities.
  • killvxk/POCS GitHub stars - Contains PoC codes for different vulnerabilities, usable for vulnerability discovery and testing.
  • kevinhous30/Vaultiris GitHub stars - Automated CVE monitoring tool for PoC identification and vulnerability detail viewing.
  • Kento-Sec/poc GitHub stars - Security vulnerability detection scripts for multiple brands and models, suitable for security assessment and testing in the network security field.
  • KayCHENvip/vulnerability-poc GitHub stars - Contains vulnerability information for various open-source software and frameworks, usable for vulnerability discovery and testing.
  • kailing0220/-T- GitHub stars - Detection and exploitation tool for arbitrary file read vulnerability in Yonyou Changjietong T+, suitable for security assessment.
  • jiayy/android_vuln_poc-exp GitHub stars - This project contains some vulnerabilities discovered by the author, including CVEs related to Android, Linux, QEMU, and Mosec-2016.
  • jas502n/CVE-2019-20197 GitHub stars - Nagios XI remote command execution vulnerability PoC.
  • ishell/Exploits-Archives GitHub stars - Contains various exploit codes from 2000 to 2013, suitable for security testing and defense.
  • Immersive-Labs-Sec/CVE-2021-32648 GitHub stars - This project named 'CVE-2021-32648' contains PoC code to demonstrate the principle of the OctoberCMS authentication bypass vulnerability (CVE-2021-32648).
  • hmoytx/WVS GitHub stars - WVS is a CMS vulnerability scanning tool written in Python, including directory scanning, online identification, and providing PoCs for over 300 vulnerabilities.
  • Hacker5preme/Exploits GitHub stars - Contains various developed exploit programs, usable for vulnerability discovery and testing.
  • h0tak88r/nuclei_templates GitHub stars - This project named 'Vulnerable Web Applications List (VWAL)' contains a list of common web application vulnerabilities, helping security experts conduct penetration testing and security assessment.
  • govbk/WIKI-POC-EXP GitHub stars - WIKI-POC-EXP is a collection library containing various vulnerability PoCs and EXPs, aimed at helping security researchers with vulnerability detection and exploitation.
  • gottburgm/Exploits GitHub stars - Personally written Perl reproducer/example code, addressing security vulnerabilities.
  • getdrive/PoC GitHub stars - This project contains multiple exploitation examples for remote code execution vulnerabilities in various software systems, including products from well-known vendors such as F5 BIG-IP, Confluence, WS_FTP Server, TeamCity, SolarView Compact, VMware Aria Operations for Networks, etc., with CVSSv3 scores of 9.8 or higher, extremely severe.
  • expzhizhuo/cve_info_data GitHub stars - This project named cve_info_data contains vulnerability resources for various IoT devices, including but not limited to routers, network devices, cameras, etc., and provides ways to obtain data from major platform vendors and links. It is mainly used for learning and consulting these vulnerability information to help users understand and fix potential security risks.
  • ErYao7/YamlRepository GitHub stars - YamlRepository is a GitHub project containing two subdirectories, Poc and finger, for storing YAML or YML format exploit codes (POC) and fingerprints.
  • Doctype02/exploitdb GitHub stars - ExploitDB is a Git repository containing various exploits, shellcode, and vulnerability-related articles. It is updated daily and provides a SearchSploit tool for content searching. This project is licensed under the GNU General Public License v2.0.
  • DawnFlame/POChouse GitHub stars - Includes various high-risk vulnerabilities that can achieve Getshell and related application Getshell techniques, one-click verification, supports batch verification, provides Metasploit and jar packages for exploiting vulnerabilities, as well as Python scripts.
  • daffainfo/AllAboutBugBounty GitHub stars - Collects various vulnerability information and bypass techniques, including file upload, cross-site scripting, denial of service attacks, etc.
  • D-Haiming/gobypoc GitHub stars - This project provides information on security vulnerabilities and weaknesses in various open-source software, helping users with vulnerability discovery and testing.
  • CVEProject/cvelistV5 GitHub stars - This project provides a list of all CVE records identified and reported to the CVE program, and offers the ability to download these records in CVE JSON 5.0 format. Users can search, download, and use the content in this repository according to the CVE program's terms of service. Additionally, the project contains all versions of current CVE records and provides baseline and hourly update ZIP files and release notes. Users can obtain these versions by cloning the repository or accessing the published pages on GitHub.
  • CVEProject/cvelist GitHub stars - A Git pilot project for public vulnerability information, storing CVE lists in CVE JSON format and automatically updating, usable for vulnerability discovery and testing.
  • CVEProject/cve-reference-ingest-data GitHub stars - This project named cve-reference-ingest-data aims to provide security vulnerability information by reading and parsing CVE references.
  • Cuerz/PoC-ExP GitHub stars - Includes various network security vulnerability exploit codes, providing learning and research resources, but strictly prohibited for illegal purposes.
  • cqr-cryeye-forks/goby-pocs GitHub stars - This project contains multiple security vulnerabilities and backdoors for open-source software, including but not limited to SQL injection, file read privilege escalation, weak passwords, command execution, etc.
  • coffeehb/Some-PoC-oR-ExP GitHub stars - This project collects various vulnerability PoCs and EXPs, including exploit codes for common web applications such as Apache, Django, MySQL, etc.
  • cckuailong/vulbase GitHub stars - Vulbase is a vulnerability library collection, runs via Docker, supports basic auth authentication, including Peiqi library and WGPsec Wiki.
  • boy-hack/airbug GitHub stars - A long-term open security vulnerability collection repository, supports vulnerability PoC submission and online verification, suitable for product testing and evaluation.
  • BLACKHAT-SSG/CVEs GitHub stars - Based on the 'Trickest' workflow, collects and splits publicly available vulnerability (CVE) PoCs by year.
  • bitfront-se/vuln-list-temp GitHub stars - Vuln-list-temp is a GitHub project that organizes vulnerability information from various sources (including CWE, GHSA, Go, NVD, and OSV). It provides developers and security professionals with a comprehensive view of known vulnerabilities to improve their security posture.
  • Balzu/PyPhish GitHub stars - PyPhish is a Python framework for simulating phishing attacks, including email templates and command-and-control server, to assess an organization's employee awareness of cybersecurity.
  • Axx8/CVE-2022-24112 GitHub stars - Exploits the batch request functionality of Apache APISIX for remote code execution (RCE), providing Python script and command examples.
  • Ares-X/VulWiki GitHub stars - Based on the Zero Group public vulnerability library security project, covering web security, system security, and IoT security vulnerabilities.
  • aquasecurity/vuln-list-nvd GitHub stars - Python script utilizing the NVD vulnerability database to collect and display security vulnerability information on the system.
  • anvbis/chrome_v8_ndays GitHub stars - Chrome browser multi-version, different types of vulnerability exploit code examples.
  • Alucard0x1/CVE-2023-30777 GitHub stars - This project is a PoC generator for a reflected cross-site scripting (XSS) vulnerability in the WordPress plugin Advanced Custom Fields, usable for testing if the target system is vulnerable.
  • 4ra1n/super-xray GitHub stars - Super X-ray is a GUI tool based on the xray vulnerability scanner, providing a friendly user interface to make it easier for beginners. It includes various functions such as subdomain scanning, reverse proxy, etc., supports Chinese and English, making it easy to find and run PoCs. It also integrates rad linkage and supports multiple scanning modes.
  • 1979139113/0day-today-exploits GitHub stars - This project provides a large number of exploit files for vulnerability discovery and testing.
  • 1120362990/vulnerability-list GitHub stars - Vulnerability quick detection tool, supports multiple common vulnerability detections, written in Python.
  • 0xmaximus/Apache-Commons-Text-CVE-2022-42889 GitHub stars - Detection and exploitation tool for Apache Commons Text vulnerability (CVE-2022-42889).
  • 0x27/CiscoRV320Dump GitHub stars - A collection of exploit tools for Cisco RV320 routers, including configuration and diagnostic log file leakage, decryption, and remote command execution, with corresponding exploit implementations.

Security Scanning and Detection

  • u21h2/nacs GitHub stars - nacs is a security scanner with functions such as host discovery, service scanning, PoC detection, database weak password brute force, and common intranet vulnerability exploitation. Users can use this tool by providing target IP or URL, passwords and other parameters, and can choose whether to perform brute force, PoC detection, etc.

Security Integration and Deployment

  • TachiuLam/SeMF GitHub stars - Enterprise intranet security management platform, including asset management, vulnerability management, account management, knowledge base management, and automated security scanning, for internal security management.
  • naozibuhao/SecurityManageFramwork GitHub stars - Enterprise intranet security management platform, including asset management, vulnerability management, account management, knowledge base management, and automated security scanning modules, applicable for enterprise internal security management.

Vulnerability and Intelligence Libraries

  • pan-unit42/iocs GitHub stars - Collection of indicators related to Unit 42 public reports, containing IOC information for various malware and attacks, used for threat intelligence analysis in the security field.
  • omarhashem123/Security-Research GitHub stars - This project named 'CVE Vulnerability Database' contains information on multiple high-risk vulnerabilities, providing important reference value for network security protection.
  • nomi-sec/NVD-Database GitHub stars - Contains vulnerability databases from 1999 to 2023, used for vulnerability management and risk assessment in the security field.
  • justakazh/CVE_Database GitHub stars - Provides a list of Common Vulnerabilities and Exposures (CVE) from the National Vulnerability Database (NVD). Data in JSON format for easy integration and consumption.# Security Knowledge Base & Documentation
  • nosafer/nosafer.github.io GitHub stars - VulWiki is a security knowledge base based on an open-source vulnerability database, covering various web applications and system security vulnerabilities, and provides detailed vulnerability analysis and exploitation methods.
  • Micr067/Vulnerability-Wiki GitHub stars - A knowledge base that integrates multiple open-source vulnerability databases, supports multiple deployment methods, and includes the wooyun vulnerability database.

Open Source License

  • This project is licensed under the MIT License.
Download Tool