Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
0day-Rubbish — Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field. | Kitploit
उपकरण/GitHubGitHub/exploit-garbage/0day-rubbish
Vulnerability AnalysisExploitationSCADA/ICS SecurityRed TeamingCurated ResourcesAI Security
GitHubexploit-garbage/0day-rubbish

0day-Rubbish

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance the field.

रिपॉजिटरी देखें
614686 दिन पहलेKitploit द्वारा समीक्षित
वेबसाइट

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

0day Rubbish

0day vulnerabilities have become rubbish in the AI era.

License: MIT Latest batch Max CVSS PoC Website Watchers Discussions Last commit

🌐 Official Website: https://0day-rubbish.com/blog


🎯 Why This Exists

Traditional vulnerability disclosure is broken. It's slow, bureaucratic, and ineffective. In the AI era, we can mass-produce 0days at scale—making individual vulnerabilities less valuable but more impactful when disclosed directly.

We believe event-driven security hardening is the most effective approach: only when vendors face real, exploitable threats do they prioritize fixes.

🔄 Our Disclosure Process

Step 1: AI Discovery

Our automated AI systems continuously scan for vulnerabilities across real-world software, identifying potential 0-days through pattern analysis, fuzzing, and intelligent code review.

Step 2: Verification & PoC Development

Each finding undergoes manual validation. We develop working proof-of-concept exploits to confirm exploitability and assess real-world impact.

Step 3: Periodic Public Disclosure

Every week — Monday or Tuesday — we disclose a new batch of verified, exploitable 0-day vulnerabilities we've discovered and validated:

  • Full technical analysis and root cause
  • Working PoC exploit code
  • Affected versions and systems
  • Impact assessment
  • Recommended mitigations

No delays. No bureaucracy. Just facts.

To all vendors: We hope you can complete fixes before hackers exploit these vulnerabilities.

⚡ Core Principles

  • Real-world impact only: We disclose only vulnerabilities that affect real-world systems with actual user bases
  • No worthless targets: Non-exploitable vulnerabilities or devices with negligible user adoption are excluded—they're rubbish with zero value
  • Speed over protocol: Direct disclosure drives faster action than traditional channels
  • Proof over claims: Every disclosure includes working exploits
  • Impact over quantity: Focus on high-severity, widely-deployed vulnerabilities
  • Transparency: Full technical details, no hidden agendas
  • Non-profit: Driven by passion for security research, not financial gain

🤝 Collaboration

We partner with:

  • Top AI model providers advancing automated security research
  • Security researchers exploring AI-powered discovery

🤖 AI Models Used

Our automated vulnerability discovery leverages cutting-edge large language models from leading AI providers:

  • Anthropic (Claude) - Deep security pattern recognition and reasoning
  • OpenAI - Advanced reasoning and code analysis
  • DeepSeek - Specialized vulnerability detection
  • Z.ai (GLM) - Long-context code analysis
  • Moonshot (Kimi) - Long-context security analysis

📋 Disclosed Vulnerabilities

An AI-driven research process (multi-LLM ensemble: Claude, OpenAI, DeepSeek, GLM, Kimi) discovers 0-days in real-world enterprise software. Every advisory below ships a full root-cause analysis plus a working, reproducible exploit script — no detection-only writeups, no withheld details.

Latest Batch — Batch 12 (8 advisories)

Management planes, device controllers and data-integration runtimes — where the authenticated administrator turns out to be one configuration write away from root.

#ProductAffected VersionCVSSClassAdvisory & PoC
1Lightstreamer Server (ENTERPRISE)7.4.8 build 35068.1 *Unauthenticated JMX diagnostic command → jvmtiAgentLoad → native code execution as the service user (root in the verified deployment)jvmtiAgentLoad → OS command execution
2Lightstreamer Server7.4.8 build 35069.8 *Shipped placeholder JMX/RMI credentials → MLet remote class loading → rootplaceholder creds → MLet → root
3Logo Netsis NetOpenX REST2.0.6.99.8 *Unauthenticated SQL injection in the OAuth token endpoint → xp_cmdshell → SYSTEMOAuth endpoint SQLi → xp_cmdshell → SYSTEM
4Safe Software FME Flow2026.2 build 263338.8 *Authenticated Zip-Slip in StoreManager.extract → arbitrary file write → JSP compiled and run under the Tomcat service accountzip entry name → arbitrary write → code execution
5MultiTech Conduit AEP6.3.67.2Authenticated import_config uploaded-filename command injection → rootfilename → MTS::System::cmd → root
6Lantronix SGX51509.13.0.0R77.2 *Authenticated FsBrowseClean command injection → rootFsBrowseClean → newline vector → root
7Cambium cnMatrix EX3024F6.2.1-r47.2 *Authenticated SSL certificate CSR command injection (COMMON_NAME) → system() → rootCSR COMMON_NAME → openssl req → root
8Server Technology PRO3X rack PDUspdu-pro3x-030600 build 466407.2 *Authenticated listener program override in port_mux → execv as rootlistener program → execv → root
टूल डाउनलोड करें