Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
0day-Rubbish — Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field. | Kitploit
Herramientas/GitHubGitHub/exploit-garbage/0day-rubbish
Vulnerability AnalysisExploitationSCADA/ICS SecurityRed TeamingCurated ResourcesAI Security
GitHubexploit-garbage/0day-rubbish

0day-Rubbish

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field.

Ver RepositorioSitio web
61469hace 6 díasRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

0day Rubbish

0day vulnerabilities have become rubbish in the AI era.

License: MIT Latest batch Max CVSS PoC Website Watchers Discussions Last commit

🌐 Official Website: https://0day-rubbish.com/blog


🎯 Why This Exists

Traditional vulnerability disclosure is broken. It's slow, bureaucratic, and ineffective. In the AI era, we can mass-produce 0days at scale—making individual vulnerabilities less valuable but more impactful when disclosed directly.

We believe event-driven security hardening is the most effective approach: only when vendors face real, exploitable threats do they prioritize fixes.

🔄 Our Disclosure Process

Step 1: AI Discovery

Our automated AI systems continuously scan for vulnerabilities across real-world software, identifying potential 0-days through pattern analysis, fuzzing, and intelligent code review.

Step 2: Verification & PoC Development

Each finding undergoes manual validation. We develop working proof-of-concept exploits to confirm exploitability and assess real-world impact.

Step 3: Periodic Public Disclosure

Every week — Monday or Tuesday — we disclose a new batch of verified, exploitable 0-day vulnerabilities we've discovered and validated:

  • Full technical analysis and root cause
  • Working PoC exploit code
  • Affected versions and systems
  • Impact assessment
  • Recommended mitigations

No delays. No bureaucracy. Just facts.

To all vendors: We hope you can complete fixes before hackers exploit these vulnerabilities.

⚡ Core Principles

  • Real-world impact only: We disclose only vulnerabilities that affect real-world systems with actual user bases
  • No worthless targets: Non-exploitable vulnerabilities or devices with negligible user adoption are excluded—they're rubbish with zero value
  • Speed over protocol: Direct disclosure drives faster action than traditional channels
  • Proof over claims: Every disclosure includes working exploits
  • Impact over quantity: Focus on high-severity, widely-deployed vulnerabilities
  • Transparency: Full technical details, no hidden agendas
  • Non-profit: Driven by passion for security research, not financial gain

🤝 Collaboration

We partner with:

  • Top AI model providers advancing automated security research
  • Security researchers exploring AI-powered discovery

🤖 AI Models Used

Our automated vulnerability discovery leverages cutting-edge large language models from leading AI providers:

  • Anthropic (Claude) - Deep security pattern recognition and reasoning
  • OpenAI - Advanced reasoning and code analysis
  • DeepSeek - Specialized vulnerability detection
  • Z.ai (GLM) - Long-context code analysis
  • Moonshot (Kimi) - Long-context security analysis

📋 Disclosed Vulnerabilities

An AI-driven research process (multi-LLM ensemble: Claude, OpenAI, DeepSeek, GLM, Kimi) discovers 0-days in real-world enterprise software. Every advisory below ships a full root-cause analysis plus a working, reproducible exploit script — no detection-only writeups, no withheld details.

Latest Batch — Batch 12 (8 advisories)

Management planes, device controllers and data-integration runtimes — where the authenticated administrator turns out to be one configuration write away from root.

#ProductAffected VersionCVSSClassAdvisory & PoC
1Lightstreamer Server (ENTERPRISE)7.4.8 build 35068.1 *Unauthenticated JMX diagnostic command → jvmtiAgentLoad → native code execution as the service user (root in the verified deployment)jvmtiAgentLoad → OS command execution
2Lightstreamer Server7.4.8 build 35069.8 *Shipped placeholder JMX/RMI credentials → MLet remote class loading → rootplaceholder creds → MLet → root
3Logo Netsis NetOpenX REST2.0.6.99.8 *Unauthenticated SQL injection in the OAuth token endpoint → xp_cmdshell → SYSTEMOAuth endpoint SQLi → xp_cmdshell → SYSTEM
4Safe Software FME Flow2026.2 build 263338.8 *Authenticated Zip-Slip in StoreManager.extract → arbitrary file write → JSP compiled and run under the Tomcat service accountzip entry name → arbitrary write → code execution
5MultiTech Conduit AEP6.3.67.2Authenticated import_config uploaded-filename command injection → rootfilename → MTS::System::cmd → root
6Lantronix SGX51509.13.0.0R77.2 *Authenticated FsBrowseClean command injection → rootFsBrowseClean → newline vector → root
7Cambium cnMatrix EX3024F6.2.1-r47.2 *Authenticated SSL certificate CSR command injection (COMMON_NAME) → system() → rootCSR COMMON_NAME → openssl req → root
8Server Technology PRO3X rack PDUspdu-pro3x-030600 build 466407.2 *Authenticated listener program override in port_mux → execv as rootlistener program → execv → root
Descargar herramienta