


Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.


Gather and update all available and newest CVEs with their PoC.

AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more


A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938…

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform…

This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.