Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Strumenti/GitHubGitHub/ghosttroops/top
Escalation di PrivilegiAnalisi delle VulnerabilitàExploitSfruttamento di Applicazioni WebPenetration TestingRed TeamingRisorse Curate
GitHubghosttroops/top

TOP

TOP Tutti bugbounty pentesting CVE-2023- POC Exp RCE esempio payload Cose

Vedi Repository
7311286810h 46m faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Sito web

Tweet Follow on Twitter GitHub Followers Top Langs

TOP

all Top Top Top_Codeql TOP All bugbounty pentesting CVE-2022- POC Exp Things

Table of Contents

  • 2026 year top total 30
  • 2025 year top total 30
  • 2024 year top total 30
  • 2023 year top total 30
  • 2022 year top total 30
  • 2021 year top total 30
  • 2020 year top total 30
  • 2019 year top total 30
  • 2018 year top total 30

2026

2025

2024

2022

2021

2020

2018

2017

Donazione

Wechat PayAliPayPaypalBTC PayBCH Pay
paypal [email protected]
Scarica lo strumento
starupdated_atnameurldes
40602026-09-05T18:54:27Zcopy-fail-CVE-2026-31431https://github.com/theori-io/copy-fail-CVE-2026-31431Copy Fail (CVE-2026-31431): LPE del kernel Linux vecchia di 9 anni trovata da Xint Code di Theori
9162026-09-02T14:29:52Zwp2shell-PoChttps://github.com/sowarma/wp2shell-PoCProof-of-concept della catena RCE CVE-2026-63030 & CVE-2026-60137
7722026-09-05T23:36:29Zwp2shell-pochttps://github.com/Icex0/wp2shell-pocwp2shell (CVE-2026-63030 & CVE-2026-60137) - catena RCE completa
1812026-08-20T10:42:34Znext-16.2.4-pocshttps://github.com/dwisiswant0/next-16.2.4-pocsRaccolta di PoC di sicurezza per Next.js v16.2.4 (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572)
9332026-09-05T19:06:56ZBYOVDhttps://github.com/BlackSnufkin/BYOVDCasi d'uso di ricerca BYOVD con scoperta di driver vulnerabili e metodologia di reverse engineering. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
5722026-09-04T17:20:17Zcve_2026_31431https://github.com/rootsecdev/cve_2026_31431Exploit POC per CVE_2026_31431
7392026-09-06T02:36:18Zghostlock-apphttps://github.com/YuKongA/ghostlock-appApp GhostLock con esecuzione One-Tap (CVE-2026-43499)
3262026-09-03T07:37:39ZCVE-2026-54121https://github.com/aniqfakhrul/CVE-2026-54121Certighost POC
5322026-09-03T19:17:51Zcve-2026-41940-PoChttps://github.com/lanicer/cve-2026-41940-PoCUno strumento per il bypass dell'autenticazione di cPanel e WHM
2392026-09-05T22:29:13ZCVE-2026-43499-popsiclehttps://github.com/x-spy/CVE-2026-43499-popsicleImplementazione di CVE-2026-43499 per 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
2122026-08-24T15:13:49ZCVE-2026-41089https://github.com/0xABCD01/CVE-2026-41089PoC di CVE-2026-41089 — buffer overflow nello stack di Netlogon CLDAP (CVSS 9.8 CRITICAL)
2592026-09-02T02:28:06ZCVE-2026-21858https://github.com/Chocapikk/CVE-2026-21858n8n Ni8mare - Catena da lettura arbitraria di file non autenticata a RCE (CVSS 10.0)
11132026-09-06T01:24:04ZRoot-My-Galaxyhttps://github.com/BuSung-dev/Root-My-GalaxyInstaller KSU per firmware Samsung Galaxy supportati con CVE-2026-43499
2622026-08-30T07:08:06ZCVE-2026-40369-EXPLOIThttps://github.com/orinimron123/CVE-2026-40369-EXPLOITCodice exploit completo per CVE-2026-40369 - Una vulnerabilità di scrittura arbitraria nel kernel di Windows che consente l'escape dalla sandbox del browser dal processo di rendering di tutti i browser
2072026-09-03T10:13:28ZCVE-2026-24061https://github.com/SafeBreach-Labs/CVE-2026-24061Sfruttamento di CVE-2026-24061
1562026-09-05T22:29:10ZCVE-2026-43499https://github.com/MobiusM/CVE-2026-43499PoC di CVE-2026-43499
3612026-08-31T10:04:28Zcopyfail-gohttps://github.com/badsectorlabs/copyfail-goUn'implementazione in Go di copyfail (CVE-2026-31431)
1742026-09-04T12:54:40ZCVE-2026-62911https://github.com/hypnguyen1209/CVE-2026-62911POC di RCE pre-auth su Exchange
1062026-09-02T14:50:34Zwp2shellhttps://github.com/0xsha/wp2shellCVE-2026-63030 + CVE-2026-60137 - "wp2shell": RCE non autenticata nel core di WordPress
8242026-08-29T02:46:00ZCVE-2026-24061https://github.com/jacubes/CVE-2026-24061PoC di exploit per CVE-2026-24061
4962026-09-04T11:37:28ZcPanelSniperhttps://github.com/ynsmroztas/cPanelSniperCVE-2026-41940 — Bypass dell'autenticazione di cPanel & WHM tramite iniezione CRLF nel file di sessione
882026-09-05T14:30:39ZCVE-2026-75604-pochttps://github.com/rafabd1/CVE-2026-75604-pocPoC di RCE su Windows in Next.js CVE-2026-75604
2122026-09-05T15:31:02ZResetNightmarehttps://github.com/Semperis-Community/ResetNightmareStrumento POC per ResetNightmare (CVE-2026-27912)
1282026-08-19T06:30:54ZCVE-2026-20817https://github.com/oxfemale/CVE-2026-20817Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Exploit proof-of-concept che dimostra l'escalation di privilegi locale tramite il servizio WER.
3172026-09-06T01:32:07ZRoot-My-Pixelhttps://github.com/alex193a/Root-My-PixelJailbreak di telefoni Google Pixel supportati con CVE-2026-43499
1012026-09-04T19:55:40ZCVE-2026-42980-POChttps://github.com/G4sp4rCS/CVE-2026-42980-POCCVE-2026-42980 EXPLOIT PUBBLICO + RICERCA
462026-09-03T14:49:43Zsamsung-android-lpehttps://github.com/Vikramaditya015/samsung-android-lpePoc per CVE-2026-20980, CVE-2026-20981, CVE-2026-20982
612026-09-05T16:57:13Zwp2shell-scannerhttps://github.com/ZephrFish/wp2shell-scannerScanner per CVE-2026-63030, CVE-2026-60137, wp2shell
1112026-08-30T13:42:25ZCVE-2026-31431-Advanced-Exploithttps://github.com/Sndav/CVE-2026-31431-Advanced-ExploitCVE-2026-31431 纯文件利用
1202026-09-03T20:31:36ZCVE-2026-41651https://github.com/Vozec/CVE-2026-41651
starupdated_atnameurldes
14312026-09-01T11:54:27ZCVE-2025-55182https://github.com/msanft/CVE-2025-55182Spiegazione e PoC RCE completo per CVE-2025-55182
24582026-09-05T16:31:41Zreact2shell-scannerhttps://github.com/assetnote/react2shell-scannerMeccanismo di rilevamento ad alta affidabilità per RCE in RSC/Next.js (CVE-2025-55182 & CVE-2025-66478)
7932026-08-24T12:23:34ZCVE-2025-55182-researchhttps://github.com/ejpir/CVE-2025-55182-researchPOC di CVE-2025-55182
4932026-08-11T09:12:24ZCVE-2018-20250https://github.com/WyAtu/CVE-2018-20250exp per https://research.checkpoint.com/extracting-code-execution-from-winrar
7162026-09-02T03:40:10ZCVE-2025-33073https://github.com/mverschu/CVE-2025-33073Exploit PoC per la falla SMB di riflessione NTLM.
9332026-09-05T19:06:56ZBYOVDhttps://github.com/BlackSnufkin/BYOVDCasi d'uso di ricerca BYOVD con scoperta di driver vulnerabili e metodologia di reverse engineering. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
5302026-08-30T23:03:21ZCVE-2025-32463_chwoothttps://github.com/pr0v3rbs/CVE-2025-32463_chwootEscalation di privilegi a root tramite il binario sudo con opzione chroot. CVE-2025-32463
2502026-08-23T00:40:02ZIngressNightmare-PoChttps://github.com/hakaioffsec/IngressNightmare-PoCQuesto è un codice PoC per sfruttare le vulnerabilità IngressNightmare (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 e CVE-2025-1974).
3442026-08-24T14:52:54Zredis_exploithttps://github.com/raminfp/redis_exploitCVE-2025-49844 (RediShell)
4762026-09-05T19:01:51ZCVE-2025-32463https://github.com/kh4sh3i/CVE-2025-32463Escalation di privilegi locale a root tramite sudo chroot su Linux
2682026-08-24T14:52:49ZCVE-2025-48799https://github.com/Wh04m1001/CVE-2025-48799
3152026-08-15T22:24:28ZCVE-2025-53770-Exploithttps://github.com/soltanali0/CVE-2025-53770-ExploitStrumento di exploit per l'iniezione di WebPart in SharePoint
1422026-08-14T00:51:12ZNextjs_RCE_Exploit_Toolhttps://github.com/pyroxenites/Nextjs_RCE_Exploit_ToolExploit per CVE-2025-55182 & CVE-2025-66478
3162026-08-29T00:10:14ZCVE-2025-55182https://github.com/emredavut/CVE-2025-55182Rilevatore di vulnerabilità RCE in RSC/Next.js & estensione Chrome PoC – CVE-2025-55182 & CVE-2025-66478
10582026-08-29T11:37:43ZReact2Shell-CVE-2025-55182-original-pochttps://github.com/lachlan2k/React2Shell-CVE-2025-55182-original-pocProof-of-Concept originali per React2Shell CVE-2025-55182
4082026-09-04T04:29:58ZCVE-2025-24071_PoChttps://github.com/0x6rss/CVE-2025-24071_PoCCVE-2025-24071: fuga di hash NTLM tramite estrazione RAR/ZIP e file .library-ms
1642026-07-15T09:04:59ZAirBorne-PoChttps://github.com/ekomsSavior/AirBorne-PoCpoc per CVE-2025-24252 & CVE-2025-24132
1982026-08-06T15:21:14ZCVE-2025-21298https://github.com/ynwarcs/CVE-2025-21298Proof of concept e dettagli per CVE-2025-21298
2152026-08-17T06:27:29ZCVE-2025-32023https://github.com/leesh3288/CVE-2025-32023PoC & Exploit per CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"
2022026-09-02T23:45:49ZiOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201CVE-2025-31200 è una RCE zero-day, zero-click in AudioConverterService di iOS CoreAudio, attivata da un file audio malevolo tramite iMessage/SMS. Lo sfruttamento ha aggirato Blastdoor, ha consentito l'escalation al kernel (CVE-2025-31201) e ha permesso il furto di token fino alla patch in iOS 18.4.1 (16 aprile 2025).
1962026-07-20T18:42:16ZCVE-2025-30208-EXPhttps://github.com/ThumpBo/CVE-2025-30208-EXPCVE-2025-30208-EXP
1902026-03-25T19:46:42ZRSC-Detect-CVE-2025-55182https://github.com/alptexans/RSC-Detect-CVE-2025-55182RSC Detect CVE 2025 55182
3852026-08-11T06:04:12ZColorOS-CVE-2025-10184https://github.com/yuuouu/ColorOS-CVE-2025-10184ColorOS短信漏洞,以及用户自救方案
2832026-08-31T11:32:54ZCVE-2025-55182-advanced-scanner-https://github.com/zack0x01/CVE-2025-55182-advanced-scanner-
4322026-08-30T22:41:40ZNext.js-RSC-RCE-Scanner-CVE-2025-66478https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478Uno scanner da riga di comando per il rilevamento in batch delle versioni delle applicazioni Next.js e per determinare se sono interessate dalla vulnerabilità CVE-2025-66478.
1972026-08-27T11:19:26ZPOC-CVE-2025-24813https://github.com/absholi7ly/POC-CVE-2025-24813Questo repository contiene uno script Proof of Concept (PoC) automatizzato per sfruttare CVE-2025-24813, una vulnerabilità di Remote Code Execution (RCE) in Apache Tomcat. La vulnerabilità consente a un attaccante di caricare un payload serializzato malevolo sul server, portando all'esecuzione di codice arbitrario tramite deserializzazione quando vengono soddisfatte condizioni specifiche.
1512026-07-23T05:00:18ZCVE-2025-11001https://github.com/pacbypass/CVE-2025-11001Exploit per CVE-2025-11001 o CVE-2025-11002
912026-08-03T04:47:49ZIngressNightmare-POCshttps://github.com/sandumjacob/IngressNightmare-POCsCVE-2025-1974
2322026-09-03T19:51:55ZCVE-2025-21333-POChttps://github.com/MrAle98/CVE-2025-21333-POCExploit POC per il buffer overflow basato su heap CVE-2025-21333. Sfrutta i dati di stato WNF e I/O ring IOP_MC_BUFFER_ENTRY
3542026-08-25T14:17:44Zo3_finds_cve-2025-37899https://github.com/SeanHeelan/o3_finds_cve-2025-37899Materiali per il post del blog sul ritrovamento di CVE-2025-37899 con o3
starupdated_atnameurldes
24582026-09-01T15:26:46ZCVE-2024-1086https://github.com/Notselwyn/CVE-2024-1086Exploit Proof-of-Concept universale di escalation di privilegi locale per CVE-2024-1086, funzionante sulla maggior parte dei kernel Linux tra v5.14 e v6.6, inclusi Debian, Ubuntu e KernelCTF. Il tasso di successo è del 99,4% nelle immagini KernelCTF.
6922026-09-01T03:08:23ZCVE-2024-38063https://github.com/ynwarcs/CVE-2024-38063poc per CVE-2024-38063 (RCE in tcpip.sys)
4972026-09-04T20:23:59Zcve-2024-6387-pochttps://github.com/zgzhang/cve-2024-6387-pocuna race condition nel signal handler del server OpenSSH (sshd)
5202026-08-21T18:07:43ZCVE-2024-49113https://github.com/SafeBreach-Labs/CVE-2024-49113LdapNightmare è uno strumento PoC che verifica un Windows Server vulnerabile rispetto a CVE-2024-49113
5332026-07-10T06:04:54Zgit_rcehttps://github.com/amalmurali47/git_rceExploit PoC per CVE-2024-32002
5282026-09-02T11:37:54ZCVE-2024-6387_Checkhttps://github.com/xaitax/CVE-2024-6387_CheckCVE-2024-6387_Check è uno strumento leggero ed efficiente progettato per identificare server che eseguono versioni vulnerabili di OpenSSH
2242026-08-24T14:52:32ZCVE-2024-38077https://github.com/qi4L/CVE-2024-38077RCE causata da un buffer overflow nello heap di RDL
3352026-08-15T23:13:07ZCVE-2024-21338https://github.com/hakaioffsec/CVE-2024-21338Escalation di privilegi locale da Admin a Kernel su sistemi operativi Windows 10 e Windows 11 con HVCI abilitato.
3782026-09-02T00:38:43Zcve-2024-6387-pochttps://github.com/acrono/cve-2024-6387-pocPoC a 32-bit per CVE-2024-6387 — mirror dell'originale 7etsuo/cve-2024-6387-poc
3302026-08-12T11:23:08ZCVE-2024-0044https://github.com/0xbinder/CVE-2024-0044CVE-2024-0044: una vulnerabilità di gravità elevata "run-as any app" che interessa le versioni di Android 12 e 13
3222026-09-03T14:04:19ZCVE-2024-4577https://github.com/watchtowrlabs/CVE-2024-4577PoC di Remote Code Execution per PHP CGI Argument Injection (CVE-2024-4577)
1352026-08-18T13:26:58Zapache-vulnerability-testinghttps://github.com/mrmtwoj/apache-vulnerability-testingStrumento di test delle vulnerabilità di Apache HTTP Server
2892026-08-15T23:13:15ZCVE-2024-30088https://github.com/tykawaii98/CVE-2024-30088
2802026-09-03T06:39:26ZCVE-2024-21413https://github.com/CMNatic/CVE-2024-21413PoC di CVE-2024-21413 per il laboratorio THM
35532026-09-03T02:30:53Zxzbothttps://github.com/amlweems/xzbotnote, honeypot e demo di exploit per la backdoor xz (CVE-2024-3094)
2072026-08-06T10:48:24ZCVE-2024-23897https://github.com/h4x0r-dz/CVE-2024-23897CVE-2024-23897
7702026-09-03T01:08:20ZCVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerabilityhttps://github.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-VulnerabilityMicrosoft-Outlook-Remote-Code-Execution-Vulnerability
2032026-08-31T10:28:00ZCVE-2024-4367-PoChttps://github.com/LOURC0D3/CVE-2024-4367-PoCProof of Concept per CVE-2024-4367 & CVE-2024-34342
2712026-08-28T14:55:35ZCVE-2024-49138-POChttps://github.com/MrAle98/CVE-2024-49138-POCExploit POC per CVE-2024-49138
1942026-08-29T10:01:47ZCVE-2024-6387https://github.com/Karmakstylez/CVE-2024-6387Vulnerabilità di esecuzione di codice remoto non autenticato nel server OpenSSH (CVE-2024-6387)
92026-08-15T23:13:20ZCVE-2024-38077-POChttps://github.com/SecStarBot/CVE-2024-38077-POC
2352026-07-27T12:00:41ZCVE_2024_30078_POC_WIFIhttps://github.com/blkph0x/CVE_2024_30078_POC_WIFIconcetto di base per l'ultima CVE del driver wifi di Windows
1802026-08-10T14:45:08ZCVE-2024-25600https://github.com/Chocapikk/CVE-2024-25600Esecuzione di codice remoto non autenticata – Bricks <= 1.9.6
2172026-08-22T03:10:54ZCVE-2024-21111https://github.com/mansk1es/CVE-2024-21111Vulnerabilità di Elevation of Privilege (escalation di privilegi locale) in Oracle VirtualBox
1362026-08-15T23:13:25ZCVE-2024-7479_CVE-2024-7481https://github.com/PeterGabaldon/CVE-2024-7479_CVE-2024-7481PoC di escalation di privilegi da utente a kernel in TeamViewer. CVE-2024-7479 e CVE-2024-7481. ZDI-24-1289 e ZDI-24-1290. TV-2024-1006.
1472026-08-10T13:29:55ZCVE-2024-38200https://github.com/passtheticket/CVE-2024-38200CVE-2024-38200 & CVE-2024-43609 - Vulnerabilità di divulgazione NTLMv2 in Microsoft Office
812026-07-27T12:00:40ZCVE-2024-30078-https://github.com/lvyitian/CVE-2024-30078-Script di rilevamento ed esecuzione di comandi per CVE-2024-30078
872026-08-15T22:24:27ZCVE-2024-40725-CVE-2024-40898https://github.com/TAM-K592/CVE-2024-40725-CVE-2024-40898CVE-2024-40725 e CVE-2024-40898, che interessano le versioni di Apache HTTP Server dalla 2.4.0 alla 2.4.61. Queste falle rappresentano rischi significativi per i server web di tutto il mondo, potendo portare alla divulgazione del codice sorgente e ad attacchi di server-side request forgery (SSRF).
1122026-08-30T11:11:36ZCVE-2024-6387https://github.com/l0n3m4n/CVE-2024-6387PoC - Vulnerabilità di esecuzione di codice remoto non autenticato nel server OpenSSH (Scanner ed Exploit)
1582026-08-24T03:27:37ZCVE-2024-21413https://github.com/duy-31/CVE-2024-21413Vulnerabilità di divulgazione di informazioni in Microsoft Outlook (fuga di hash di password) - POC con Expect Script
starupdated_atnameurldes
---------------
4192026-07-27T12:00:10Zqq-tim-elevationhttps://github.com/vi3t1/qq-tim-elevationCVE-2023-34312
14892026-09-01T15:26:22Zcvelisthttps://github.com/CVEProject/cvelistProgramma pilota per l'invio di CVE tramite GitHub. Invio di record CVE tramite PR pilota con scadenza 30/06/2023
5062026-08-21T11:19:59ZWindows_LPE_AFD_CVE-2023-21768https://github.com/chompie1337/Windows_LPE_AFD_CVE-2023-21768Exploit LPE per CVE-2023-21768
7822026-07-29T17:11:08ZCVE-2023-38831-winrar-exploithttps://github.com/b1tg/CVE-2023-38831-winrar-exploitGeneratore di exploit per CVE-2023-38831 winrar
3832026-09-05T06:31:33ZCVE-2023-32233https://github.com/Liuk3r/CVE-2023-32233CVE-2023-32233: vulnerabilità di sicurezza nel kernel Linux
3942026-09-05T21:48:15ZCVE-2023-4911https://github.com/leesh3288/CVE-2023-4911PoC per CVE-2023-4911
4182026-07-27T12:00:05ZCVE-2023-0386https://github.com/xkaneiki/CVE-2023-0386Escalation di privilegi di CVE-2023-0386 su ubuntu22.04
1162026-08-24T14:52:11ZCVE-2023-21839https://github.com/ASkyeye/CVE-2023-21839Weblogic CVE-2023-21839 RCE (RCE con un solo clic senza dipendenze Java)
3282026-08-18T21:26:43ZCVE-2023-21752https://github.com/Wh04m1001/CVE-2023-21752
6522026-09-05T14:40:10Zkeepass-password-dumperhttps://github.com/vdohney/keepass-password-dumperPoC originale per CVE-2023-32784
2832026-07-30T00:43:58ZCVE-2023-21608https://github.com/hacksysteam/CVE-2023-21608Adobe Acrobat Reader - CVE-2023-21608 - Exploit per l'esecuzione di codice in remoto
3172026-08-20T20:28:38ZCVE-2023-4863https://github.com/mistymntncop/CVE-2023-4863
2422026-08-21T11:20:13ZCVE-2023-36874https://github.com/Wh04m1001/CVE-2023-36874
2472026-08-14T12:24:08ZCVE-2023-44487https://github.com/bcdannyboy/CVE-2023-44487Scansione di vulnerabilità di base per verificare se i server web possono essere vulnerabili a CVE-2023-44487
2282026-07-29T15:55:14ZCVE-2023-3519https://github.com/BishopFox/CVE-2023-3519Exploit RCE per CVE-2023-3519
2452026-08-10T14:45:02ZCVE-2023-7028https://github.com/Vozec/CVE-2023-7028Questo repository presenta una proof-of-concept di CVE-2023-7028
1692026-07-12T21:14:55ZCVE-2023-36745https://github.com/N1k0la-T/CVE-2023-36745
1402026-08-09T23:29:11ZCVE-2023-34362https://github.com/horizon3ai/CVE-2023-34362MOVEit CVE-2023-34362
2282026-08-25T15:16:27ZCVE-2023-20887https://github.com/sinsinology/CVE-2023-20887VMWare vRealize Network Insight RCE pre-autenticazione (CVE-2023-20887)
3452026-09-03T19:51:33ZCVE-2023-23397-POC-Powershellhttps://github.com/api0cradle/CVE-2023-23397-POC-Powershell
1832026-08-15T23:12:53ZCVE-2023-28252https://github.com/fortra/CVE-2023-28252
1362026-08-15T22:24:27ZCVE-2023-2640-CVE-2023-32629https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629GameOver(lay) Escalation di privilegi su Ubuntu
2892026-08-08T13:06:40ZCVE-2023-25690-POChttps://github.com/dhmosfunk/CVE-2023-25690-POCCVE 2023 25690 Proof of concept - una configurazione vulnerabile di mod_proxy su Apache HTTP Server versioni 2.4.0 - 2.4.55 porta a una vulnerabilità di HTTP Request Smuggling.
2412026-08-06T11:26:50ZWeblogic-CVE-2023-21839https://github.com/DXask88MA/Weblogic-CVE-2023-21839
2062026-08-31T13:38:48ZCVE-2023-46747-RCEhttps://github.com/W01fh4cker/CVE-2023-46747-RCEexploit per f5-big-ip RCE cve-2023-46747
1532026-09-04T10:06:50Zcve-2023-29360https://github.com/Nero22k/cve-2023-29360Exploit per CVE-2023-29360 che prende di mira il driver MSKSSRV.SYS
2372026-09-03T19:51:42ZCVE-2023-29357https://github.com/Chocapikk/CVE-2023-29357Vulnerabilità di escalation di privilegi in Microsoft SharePoint Server
1672026-08-17T13:31:52ZCVE-2023-25157https://github.com/win3zz/CVE-2023-25157CVE-2023-25157 - GeoServer SQL Injection - PoC
1652026-07-23T03:14:23ZWindows_MSKSSRV_LPE_CVE-2023-36802https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802Exploit LPE per CVE-2023-36802
1582026-08-21T11:20:01ZCVE-2023-23397_EXPLOIT_0DAYhttps://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAYExploit per CVE-2023-23397
starupdated_atnameurldes
4382026-09-05T06:31:04ZCVE-2022-25636https://github.com/Bonfee/CVE-2022-25636CVE-2022-25636
4612026-08-28T14:55:07ZCVE-2022-21882https://github.com/KaLendsi/CVE-2022-21882win32k LPE
11332026-08-26T03:57:20ZCVE-2022-0847-DirtyPipe-Exploithttps://github.com/Arinerron/CVE-2022-0847-DirtyPipe-ExploitUn exploit root per CVE-2022-0847 (Dirty Pipe)
3792026-07-11T17:00:38ZCVE-2022-0185https://github.com/Crusaders-of-Rust/CVE-2022-0185CVE-2022-0185
6732026-07-23T03:14:03ZCVE-2022-29072https://github.com/kagancapar/CVE-2022-290727-Zip fino alla versione 21.07 su Windows consente l'escalation di privilegi e l'esecuzione di comandi quando un file con estensione .7z viene trascinato nell'area Help>Contents.
4972026-09-01T03:56:02ZCVE-2022-0995https://github.com/Bonfee/CVE-2022-0995exploit per CVE-2022-0995
5732026-08-24T11:54:59ZCVE-2022-23222https://github.com/tr3ee/CVE-2022-23222CVE-2022-23222: escalation di privilegi locale eBPF nel kernel Linux
5282026-07-11T17:03:47ZOpenSSL-2022https://github.com/NCSC-NL/OpenSSL-2022Informazioni operative riguardanti CVE-2022-3602 e CVE-2022-3786, due vulnerabilità in OpenSSL 3
2232026-05-13T19:49:24ZSpring-Cloud-Gateway-CVE-2022-22947https://github.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947CVE-2022-22947
3602026-08-18T21:14:11ZCVE-2022-21907https://github.com/ZZ-SOCMAP/CVE-2022-21907Vulnerabilità di esecuzione di codice in remoto nello stack del protocollo HTTP CVE-2022-21907
3772026-08-21T11:19:25ZCVE-2022-29464https://github.com/hakivvi/CVE-2022-29464Exploit e writeup di WSO2 RCE (CVE-2022-29464).
7322026-09-05T06:19:39ZCVE-2022-0847-DirtyPipe-Exploitshttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-ExploitsUna raccolta di exploit e documentazione che può essere utilizzata per sfruttare la vulnerabilità Linux Dirty Pipe.
3582026-09-01T19:54:28ZCVE-2022-40684https://github.com/horizon3ai/CVE-2022-40684Una proof of concept di exploit per CVE-2022-40684 che interessa Fortinet FortiOS, FortiProxy e FortiSwitchManager
4872026-08-21T11:19:45ZCVE-2022-2588https://github.com/Markakd/CVE-2022-2588exploit per CVE-2022-2588
3872026-07-27T14:08:58ZCVE-2022-39197https://github.com/its-arun/CVE-2022-39197CobaltStrike <= 4.7.1 RCE
4142026-09-03T19:51:26ZCVE-2022-33679https://github.com/Bdenneu/CVE-2022-33679One day basato su https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
2822026-06-22T01:47:59ZCVE-2022-0847https://github.com/r1is/CVE-2022-0847CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 è una vulnerabilità di escalation di privilegi locale presente nel kernel Linux 5.8 e versioni successive. Sfruttando questa vulnerabilità, un attaccante può sovrascrivere i dati in qualsiasi file leggibile, elevando così un utente con privilegi normali a root privilegiato. Il principio della vulnerabilità CVE-2022-0847 è simile alla vulnerabilità Dirty Cow CVE-2016-5195, ma è più facile da sfruttare. L'autore della vulnerabilità l'ha denominata "Dirty Pipe"
3532026-08-20T09:45:56ZCVE-2022-21894https://github.com/Wack0/CVE-2022-21894baton drop (CVE-2022-21894): vulnerabilità di bypass della funzionalità di sicurezza Secure Boot
3252026-07-31T14:19:06ZSpring4Shell-POChttps://github.com/reznok/Spring4Shell-POCApplicazione PoC Spring4Shell (CVE-2022-22965) dockerizzata ed exploit
4602026-08-24T08:16:08ZCVE-2022-27254https://github.com/nonamecoder/CVE-2022-27254PoC per la vulnerabilità nel sistema Remote Keyless di Honda (CVE-2022-27254)
3172026-06-22T11:04:03ZCVE-2022-39197-patchhttps://github.com/burpheart/CVE-2022-39197-patchPatch per la vulnerabilità CVE-2022-39197. CVE-2022-39197 Vulnerability Patch.
5972026-09-05T18:21:18ZCVE-2022-38694_unlock_bootloaderhttps://github.com/TomKing062/CVE-2022-38694_unlock_bootloaderQuesto è un bypass della verifica della firma una tantum. Per un bypass persistente della verifica della firma, consultare https://github.com/TomKing062/CVE-2022-38691_38692
3022026-07-26T11:42:14ZCVE-2022-21971https://github.com/0vercl0k/CVE-2022-21971PoC per CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"
2652026-04-05T11:55:32ZCVE-2022-39952https://github.com/horizon3ai/CVE-2022-39952POC per CVE-2022-39952
2842026-08-24T14:52:04Zcve-2022-27255https://github.com/infobyte/cve-2022-27255
2382026-08-24T14:51:59ZCVE-2022-20699https://github.com/Audiobahn/CVE-2022-20699Cisco Anyconnect VPN RCE non autenticato (stack rwx)
2362026-08-31T15:38:57ZCVE-2022-30075https://github.com/aaronsvk/CVE-2022-30075Tp-Link Archer AX50 RCE autenticato (CVE-2022-30075)
2192026-06-02T12:40:09ZCVE-2022-34918https://github.com/veritas501/CVE-2022-34918CVE-2022-34918 netfilter nf_tables POC di escalation di privilegi locale
1152026-07-03T14:59:15ZCVE-2022-22963https://github.com/dinosn/CVE-2022-22963CVE-2022-22963 PoC
1972026-07-13T09:28:39ZCVE-2022-21882https://github.com/L4ys/CVE-2022-21882
starupdated_atnameurldes
14142026-09-01T15:26:24ZnoPachttps://github.com/cube0x0/noPacScanner ed exploiter per CVE-2021-42287/CVE-2021-42278.
20012026-09-06T00:10:43ZCVE-2021-1675https://github.com/cube0x0/CVE-2021-1675Implementazione C# e Impacket di PrintNightmare CVE-2021-1675/CVE-2021-34527
20482026-09-01T15:26:33ZCVE-2021-4034https://github.com/berdav/CVE-2021-4034CVE-2021-4034 1day
18082026-09-05T22:53:02ZCVE-2021-40444https://github.com/lockedbyte/CVE-2021-40444CVE-2021-40444 PoC
11622026-09-05T06:04:24ZCVE-2021-4034https://github.com/arthepsy/CVE-2021-4034PoC per PwnKit: vulnerabilità di escalation di privilegi locale in pkexec di polkit (CVE-2021-4034)
10232026-09-05T05:48:21ZCVE-2021-3156https://github.com/blasty/CVE-2021-3156
11082026-09-04T02:10:14ZCVE-2021-1675https://github.com/calebstewart/CVE-2021-1675Implementazione pura in PowerShell di CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
4972026-09-03T19:51:00ZCVE-2021-21972https://github.com/NS-Sp4ce/CVE-2021-21972Exploit per CVE-2021-21972
10672026-08-23T03:16:37Zsam-the-adminhttps://github.com/safebuffer/sam-the-adminSfruttamento di CVE-2021-42278 e CVE-2021-42287 per impersonare DA da un utente di dominio standard
8042026-08-26T08:10:59ZCVE-2021-3156https://github.com/worawit/CVE-2021-3156Exploit Sudo Baron Samedit
8332026-09-03T02:54:08ZCVE-2021-40444https://github.com/klezVirus/CVE-2021-40444CVE-2021-40444 - Exploit RCE di Microsoft Office Word completamente weaponizzato
4262026-08-23T20:16:03ZCVE-2021-1732-Exploithttps://github.com/KaLendsi/CVE-2021-1732-ExploitExploit per CVE-2021-1732
10232026-09-05T23:38:24ZnoPachttps://github.com/Ridter/noPacSfruttamento di CVE-2021-42278 e CVE-2021-42287 per impersonare DA da un utente di dominio standard
8272026-07-31T15:53:30ZCVE-2021-31166https://github.com/0vercl0k/CVE-2021-31166Proof of concept per CVE-2021-31166, un use-after-free in HTTP.sys attivato da remoto.
8602026-08-17T13:31:50ZCVE-2021-44228-Scannerhttps://github.com/logpresso/CVE-2021-44228-ScannerScanner di vulnerabilità e patch di mitigazione per Log4j2 CVE-2021-44228
18482026-09-04T08:37:46Zlog4j-shell-pochttps://github.com/kozmer/log4j-shell-pocUna Proof-Of-Concept per la vulnerabilità CVE-2021-44228.
11412026-08-30T16:31:59Zlog4shell-vulnerable-apphttps://github.com/christophetd/log4shell-vulnerable-appApplicazione web Spring Boot vulnerabile a Log4Shell (CVE-2021-44228).
4432026-09-03T09:48:19ZCVE-2021-3493https://github.com/briskets/CVE-2021-3493Escalation di privilegi locale su Ubuntu OverlayFS
3252026-05-31T05:04:48ZCVE-2021-1675-LPEhttps://github.com/hlldz/CVE-2021-1675-LPEEdizione Local Privilege Escalation per CVE-2021-1675/CVE-2021-34527
1862026-07-17T09:01:22Zexprologhttps://github.com/herwonowr/exprologPoC della catena di exploit completa di ProxyLogon (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065)
4392026-06-20T15:36:09Zlog4j-finderhttps://github.com/fox-it/log4j-finderTrova versioni vulnerabili di Log4j2 su disco e anche all'interno di file Java Archive (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)
4292026-07-29T10:34:22ZCVE-2021-3156https://github.com/stong/CVE-2021-3156PoC per CVE-2021-3156 (sudo heap overflow)
1762026-08-17T13:31:49ZProxyVulnshttps://github.com/hosch3n/ProxyVulns[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Exploit per il bug RawIdentity corretto. [ProxyOracle] Catene di exploit CVE-2021-31195 & CVE-2021-31196. [ProxyShell] Catene di exploit CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207.
2872026-08-28T07:19:34ZCVE-2021-22205https://github.com/Al1ex/CVE-2021-22205CVE-2021-22205& GitLab CE/EE RCE
34222026-08-24T02:07:57Zlog4j-scanhttps://github.com/fullhunt/log4j-scanUno scanner completamente automatizzato, accurato ed esteso per trovare log4j RCE CVE-2021-44228
2682026-09-03T19:51:00ZCVE-2021-21972https://github.com/horizon3ai/CVE-2021-21972Exploit Proof of Concept per vCenter CVE-2021-21972
3012026-09-04T02:23:31ZCVE-2021-36260https://github.com/Aiminsun/CVE-2021-36260vulnerabilità di command injection nel server web di alcuni prodotti Hikvision. A causa della convalida insufficiente dell'input, un attaccante può sfruttare la vulnerabilità per lanciare un attacco di command injection inviando alcuni messaggi con comandi malevoli.
1472026-05-23T10:52:31ZCVE-2021-41773_CVE-2021-42013https://github.com/inbug-team/CVE-2021-41773_CVE-2021-42013Strumento di rilevamento in batch per le vulnerabilità CVE-2021-41773 CVE-2021-42013
3252026-08-21T18:45:26ZCVE-2021-34527https://github.com/JohnHammond/CVE-2021-34527
1222026-09-03T09:07:12Zproxyshellhttps://github.com/horizon3ai/proxyshellProof of Concept per CVE-2021-34473, CVE-2021-34523 e CVE-2021-31207
starupdated_atnameurldes
42892026-09-04T01:55:44Zexphubhttps://github.com/zhzyker/exphubExphub[libreria di script di exploit] include script di exploit per Weblogic, Struts2, Tomcat, Nexus, Solr, Jboss, Drupal, con l'aggiunta più recente di CVE-2020-14882, CVE-2020-11444, CVE-2020-10204, CVE-2020-10199, CVE-2020-1938, CVE-2020-2551, CVE-2020-2555, CVE-2020-2883, CVE-2019-17558, CVE-2019-6340
18322026-09-01T15:26:49ZCVE-2020-1472https://github.com/bvcyber/CVE-2020-1472Strumento di test per CVE-2020-1472
20752026-09-01T15:26:20ZweblogicScannerhttps://github.com/0xn0ne/weblogicScannerStrumento di scansione delle vulnerabilità di weblogic. Attualmente include la capacità di rilevare le seguenti vulnerabilità: CVE-2014-4210, CVE-2016-0638, CVE-2016-3510, CVE-2017-3248, CVE-2017-3506, CVE-2017-10271, CVE-2018-2628, CVE-2018-2893, CVE-2018-2894, CVE-2018-3191, CVE-2018-3245, CVE-2018-3252, CVE-2019-2618, CVE-2019-2725, CVE-2019-2729, CVE-2019-2890, CVE-2020-2551, CVE-2020-14750, CVE-2020-14882, CVE-2020-14883
13592026-08-21T11:17:52ZCVE-2020-0796https://github.com/danigargu/CVE-2020-0796CVE-2020-0796 - Exploit LPE di Windows SMBv3 #SMBGhost
13232026-09-03T13:04:39ZCVE-2020-1472https://github.com/dirkjanm/CVE-2020-1472PoC per Zerologon - tutti i crediti di ricerca vanno a Tom Tervoort di Secura
2872026-08-04T08:01:02ZCVE-2020-14882https://github.com/jas502n/CVE-2020-14882CVE-2020–14882、CVE-2020–14883
3282026-08-05T23:19:15Zcve-2020-0688https://github.com/Ridter/cve-2020-0688cve-2020-0688
7062026-09-02T23:02:20Zzerologonhttps://github.com/risksense/zerologonExploit per zerologon cve-2020-1472
7222026-09-04T16:53:43ZSMBGhosthttps://github.com/ly4k/SMBGhostScanner per CVE-2020-0796 - SMBv3 RCE
3532026-09-04T00:17:18ZCVEAC-2020https://github.com/thesecretclub/CVEAC-2020Bypass del controllo di integrità di EasyAntiCheat tramite l'imitazione delle modifiche alla memoria
5712026-08-15T23:12:11ZCVE-2020-0796-RCE-POChttps://github.com/jamf/CVE-2020-0796-RCE-POCPOC di esecuzione di codice in remoto per CVE-2020-0796
3742025-12-23T08:30:40ZCVE-2020-5902https://github.com/jas502n/CVE-2020-5902CVE-2020-5902 BIG-IP
1332026-07-03T05:20:29ZCVE_2020_2546https://github.com/hktalent/CVE_2020_2546CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 PoC di exploit del payload WebLogic T3 python3,
2232026-07-29T10:34:10ZSAP_RECONhttps://github.com/chipik/SAP_RECONPoC per CVE-2020-6287, CVE-2020-6286 (vulnerabilità SAP RECON)
8892026-08-11T23:19:25ZCurveBallhttps://github.com/ly4k/CurveBallPoC per CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)
2942026-08-04T08:00:45ZCNVD-2020-10487-Tomcat-Ajp-lfi-Scannerhttps://github.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-ScannerCnvd-2020-10487 / cve-2020-1938, strumento di scansione
3362026-08-04T08:00:45ZCVE-2020-2551https://github.com/Y4er/CVE-2020-2551Weblogic IIOP CVE-2020-2551
2492026-05-28T08:01:05ZBlueGatehttps://github.com/ly4k/BlueGatePoC (DoS + scanner) per CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE
3542026-08-05T23:16:25ZCVE-2020-0688https://github.com/zcgonvh/CVE-2020-0688Strumenti di exploit e rilevamento per CVE-2020-0688
7212026-08-13T09:49:27ZCVE-2020-0787-EXP-ALL-WINDOWS-VERSIONhttps://github.com/cbwang505/CVE-2020-0787-EXP-ALL-WINDOWS-VERSIONSupporta TUTTE le versioni di Windows
1012026-04-03T14:54:58Zdnspooqhttps://github.com/knqyf263/dnspooqDNSpooq - avvelenamento della cache di dnsmasq (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685)
3312026-09-03T11:41:49ZCVE-2020-0796-PoChttps://github.com/eerykitty/CVE-2020-0796-PoCPoC per attivare un buffer overflow tramite CVE-2020-0796
3982026-08-21T13:18:39ZCVE-2020-1472https://github.com/VoidSec/CVE-2020-1472Codice di exploit per CVE-2020-1472 alias Zerologon
1632026-08-04T08:00:45Zcve-2020-0688https://github.com/random-robbie/cve-2020-0688cve-2020-0688
2572026-07-29T10:33:57ZCVE-2020-0041https://github.com/bluefrostsecurity/CVE-2020-0041Exploit per il bug Android Binder CVE-2020-0041
4232026-08-19T17:33:57ZGhostcat-CNVD-2020-10487https://github.com/00theway/Ghostcat-CNVD-2020-10487Ghostcat lettura file/esecuzione codice, CNVD-2020-10487(CVE-2020-1938)
5142026-09-05T02:17:56ZCVE-2020-15368https://github.com/stong/CVE-2020-15368CVE-2020-15368, alias "Come sfruttare un driver vulnerabile"
3352026-06-30T12:15:45Zchainoffoolshttps://github.com/kudelskisecurity/chainoffoolsUna PoC per CVE-2020-0601
3372026-09-03T19:45:36ZCVE-2020-0683https://github.com/padovah4ck## 2019
starupdated_atnameurldes
---------------
20752026-09-01T15:26:20ZweblogicScannerhttps://github.com/0xn0ne/weblogicScannerStrumento di scansione delle vulnerabilità di weblogic. Attualmente include la capacità di rilevamento delle seguenti vulnerabilità: CVE-2014-4210, CVE-2016-0638, CVE-2016-3510, CVE-2017-3248, CVE-2017-3506, CVE-2017-10271, CVE-2018-2628, CVE-2018-2893, CVE-2018-2894, CVE-2018-3191, CVE-2018-3245, CVE-2018-3252, CVE-2019-2618, CVE-2019-2725, CVE-2019-2729, CVE-2019-2890, CVE-2020-2551, CVE-2020-14750, CVE-2020-14882, CVE-2020-14883
42892026-09-04T01:55:44Zexphubhttps://github.com/zhzyker/exphubExphub[libreria di script di exploit per vulnerabilità] include script di exploit per Weblogic, Struts2, Tomcat, Nexus, Solr, Jboss, Drupal, con l'aggiunta più recente di CVE-2020-14882, CVE-2020-11444, CVE-2020-10204, CVE-2020-10199, CVE-2020-1938, CVE-2020-2551, CVE-2020-2555, CVE-2020-2883, CVE-2019-17558, CVE-2019-6340
18322026-09-04T16:09:45Zphuip-fpizdamhttps://github.com/neex/phuip-fpizdamExploit per CVE-2019-11043
11822026-09-04T00:56:48ZBlueKeephttps://github.com/Ekultek/BlueKeepProof of concept per CVE-2019-0708
4962026-09-01T03:59:50ZCVE-2019-0708https://github.com/n1xbyte/CVE-2019-0708dump
6582026-07-29T10:32:54ZCVE-2019-5736-PoChttps://github.com/Frichetten/CVE-2019-5736-PoCPoC per CVE-2019-5736
3882026-08-04T08:00:31ZCVE-2019-0708https://github.com/k8gege/CVE-2019-0708Strumento di rilevamento in batch per la vulnerabilità di esecuzione di codice da remoto sul desktop remoto 3389 CVE-2019-0708 (Rdpscan Bluekeep Check)
8212026-08-18T00:34:19Zesp32_esp8266_attackshttps://github.com/Matheus-Garbelini/esp32_esp8266_attacksProof of Concept delle vulnerabilità Wi-Fi di ESP32/8266 (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588)
4332026-05-23T10:50:00ZCVE-2019-2725https://github.com/lufeirider/CVE-2019-2725CVE-2019-2725 echo dei comandi
5732026-07-16T11:27:46Zcve-2019-19781https://github.com/trustedsec/cve-2019-19781Questo è uno strumento pubblicato per la vulnerabilità di Citrix ADC (NetScaler). Lo rendiamo pubblico solo perché altri hanno pubblicato per primi il codice di exploit.
3482026-07-29T10:33:39ZCOMahawkhttps://github.com/apt69/COMahawkEscalation di privilegi: armare CVE-2019-1405 e CVE-2019-1322
3602026-07-29T10:33:28ZCVE-2019-11510https://github.com/projectzeroindia/CVE-2019-11510Exploit per la lettura arbitraria di file su Pulse Secure SSL VPN (CVE-2019-11510)
3672026-07-16T11:27:44ZCVE-2019-19781https://github.com/projectzeroindia/CVE-2019-19781Exploit di esecuzione di codice da remoto per Citrix Application Delivery Controller e Citrix Gateway [ CVE-2019-19781 ]
3332026-09-01T07:22:52ZCVE-2019-13272https://github.com/jas502n/CVE-2019-13272Linux 4.10 < 5.1.17 PTRACE_TRACEME root locale
6242026-07-29T10:33:33ZCVE-2019-11708https://github.com/0vercl0k/CVE-2019-11708Catena di exploit completa (CVE-2019-11708 e CVE-2019-9810) contro Firefox su Windows a 64 bit.
1292026-07-29T10:33:01ZCVE-2019-0604https://github.com/linhlhq/CVE-2019-0604CVE-2019-0604
3742026-08-18T07:57:54ZCVE-2019-18935https://github.com/noperator/CVE-2019-18935Exploit RCE per una vulnerabilità di deserializzazione JSON .NET in Telerik UI per ASP.NET AJAX.
3162026-07-29T10:32:54Zcve-2019-1003000-jenkins-rce-pochttps://github.com/adamyordan/cve-2019-1003000-jenkins-rce-pocProof-of-Concept RCE di Jenkins: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
2392026-07-29T10:33:05ZCVE-2019-0841https://github.com/rogue-kdc/CVE-2019-0841Codice PoC per la vulnerabilità di escalation di privilegi CVE-2019-0841
2092026-08-25T09:51:16ZCVE-2019-11932https://github.com/awakened1712/CVE-2019-11932Semplice POC per sfruttare il bug double-free di WhatsApp in DDGifSlurp in decoding.c in libpl_droidsonroids_gif
2552026-08-29T12:30:21ZCVE-2019-5786https://github.com/exodusintel/CVE-2019-5786Exploit FileReader
2672026-05-13T19:46:49ZCVE-2019-11932https://github.com/dorkerdevil/CVE-2019-11932poc di exploit del bug double-free in WhatsApp
9212026-09-01T01:54:30Zrdpscanhttps://github.com/robertdavidgraham/rdpscanUn rapido scanner per la vulnerabilità "BlueKeep" CVE-2019-0708.
2932026-08-28T14:54:44Zbluekeephttps://github.com/0xeb-bp/bluekeepLavoro pubblico per CVE-2019-0708
2492026-09-02T19:00:40ZCVE-2019-1040https://github.com/Ridter/CVE-2019-1040CVE-2019-1040 con Exchange
6812026-07-29T10:32:53Zdirty_sockhttps://github.com/initstring/dirty_sockExploit di escalation di privilegi su Linux tramite snapd (CVE-2019-7304)
1662026-07-29T10:33:36ZCVE-2019-7609https://github.com/LandGrey/CVE-2019-7609exploit CVE-2019-7609 (kibana RCE) nel modo giusto tramite script python2
32025-09-14T06:41:42ZCVE-2019-0708https://github.com/victor0013/CVE-2019-0708PoC scanner per la vulnerabilità RCE RDP CVE-2019-0708
2002026-09-01T04:11:59ZCVE-2019-16098https://github.com/Barakat/CVE-2019-16098Exploit PoC di escalation di privilegi locale per CVE-2019-16098
2082026-07-29T10:32:58ZCVE-2019-0192https://github.com/mpgn/CVE-2019-0192RCE su Apache Solr tramite deserializzazione di dati non attendibili via jmx.serviceUrl
starupdated_atnameurldes
20752026-09-01T15:26:20ZweblogicScannerhttps://github.com/0xn0ne/weblogicScannerStrumento di scansione delle vulnerabilità di weblogic. Attualmente include la capacità di rilevamento delle seguenti vulnerabilità: CVE-2014-4210, CVE-2016-0638, CVE-2016-3510, CVE-2017-3248, CVE-2017-3506, CVE-2017-10271, CVE-2018-2628, CVE-2018-2893, CVE-2018-2894, CVE-2018-3191, CVE-2018-3245, CVE-2018-3252, CVE-2019-2618, CVE-2019-2725, CVE-2019-2729, CVE-2019-2890, CVE-2020-2551, CVE-2020-14750, CVE-2020-14882, CVE-2020-14883
4992026-09-02T21:00:11ZCVE-2018-8120https://github.com/rip1s/CVE-2018-8120Exploit LPE di Windows CVE-2018-8120
4932026-08-11T09:12:24ZCVE-2018-20250https://github.com/WyAtu/CVE-2018-20250exp per https://research.checkpoint.com/extracting-code-execution-from-winrar
5342026-07-03T09:06:47ZCVE-2018-15473-Exploithttps://github.com/Rhynorater/CVE-2018-15473-ExploitExploit scritto in Python per CVE-2018-15473 con threading e formati di esportazione
5582026-09-05T01:15:33ZCVE-2018-9995_dvr_credentialshttps://github.com/ezelf/CVE-2018-9995_dvr_credentials(CVE-2018-9995) Ottenere le credenziali del DVR
3692026-07-29T10:32:50ZExchange2domainhttps://github.com/Ridter/Exchange2domainCVE-2018-8581
2532026-05-18T02:43:52ZCVE-2018-13379https://github.com/milo2012/CVE-2018-13379CVE-2018-13379
4972026-09-01T03:57:01ZCVE-2018-10933https://github.com/blacknbunny/CVE-2018-10933Ottenere una shell senza alcuna credenziale utilizzando CVE-2018-10933 (LibSSH)
2702026-07-14T20:29:03ZCVE-2018-0802https://github.com/rxwx/CVE-2018-0802Exploit PoC per CVE-2018-0802 (e opzionalmente CVE-2017-11882)
3542026-08-13T09:14:55ZCVE-2018-7600https://github.com/a2u/CVE-2018-7600💀Proof-of-Concept per CVE-2018-7600 Drupal SA-CORE-2018-002
2932026-09-02T21:43:04ZCVE-2018-8120https://github.com/alpha1ab/CVE-2018-8120Exploit CVE-2018-8120 per Win2003 Win2008 WinXP Win7
4232026-09-02T11:17:08ZCVE-2018-8897https://github.com/can1357/CVE-2018-8897Esecuzione arbitraria di codice con privilegi del kernel utilizzando CVE-2018-8897.
3312026-04-11T08:21:35ZCVE-2018-8581https://github.com/WyAtu/CVE-2018-8581CVE-2018-8581
5202026-08-16T20:26:51ZWinboxPoChttps://github.com/BasuCert/WinboxPoCProof of Concept della vulnerabilità critica di Winbox (CVE-2018-14847)
782024-08-12T19:37:50ZCVE-2018-2628https://github.com/shengqi158/CVE-2018-2628CVE-2018-2628 e CVE-2018-2893
1462026-05-13T19:46:39ZCVE-2018-13382https://github.com/milo2012/CVE-2018-13382CVE-2018-13382
1392026-07-29T10:32:13ZCVE-2018-8174_EXPhttps://github.com/Yt1g3r/CVE-2018-8174_EXPCVE-2018-8174_python
2052026-07-29T10:32:16ZCVE-2018-0296https://github.com/yassineaboukir/CVE-2018-0296Script per testare la vulnerabilità di path traversal di Cisco ASA (CVE-2018-0296) ed estrarre informazioni di sistema.
1722025-12-24T02:23:23ZCVE-2018-3245https://github.com/pyn3rd/CVE-2018-3245CVE-2018-3245-PoC
3032026-06-06T17:24:23Zstruts-pwn_CVE-2018-11776https://github.com/mazen160/struts-pwn_CVE-2018-11776Un exploit per Apache Struts CVE-2018-11776
1632026-07-29T10:32:10Zcve-2018-8120https://github.com/bigric3/cve-2018-8120
1402026-09-03T04:51:18ZCVE-2018-7600https://github.com/pimps/CVE-2018-7600Exploit per Drupal 7 <= 7.57 CVE-2018-7600
3752026-09-06T01:36:10ZGDRVLoaderhttps://github.com/zer0condition/GDRVLoaderLoader per driver non firmati che utilizza CVE-2018-19320
1792026-07-13T11:58:32ZCVE-2018-15982_EXPhttps://github.com/Ridter/CVE-2018-15982_EXPexp di CVE-2018-15982
1192026-08-01T13:49:38Zcve-2018-8453-exphttps://github.com/ze0r/cve-2018-8453-expcve-2018-8453 exp
1662026-07-29T10:31:41ZRTF_11882_0802https://github.com/Ridter/RTF_11882_0802PoC per CVE-2018-0802 e CVE-2017-11882
1672026-07-29T10:32:12ZCVE-2018-8174-msfhttps://github.com/0x09AL/CVE-2018-8174-msfCVE-2018-8174 - Exploit di corruzione della memoria di VBScript.
2672026-07-29T10:32:00Zcredssphttps://github.com/preempt/credsspUn codice che dimostra CVE-2018-0886
1402025-11-28T04:31:10ZCVE-2018-2894https://github.com/LandGrey/CVE-2018-2894Script di verifica per CVE-2018-2894 WebLogic Unrestricted File Upload che porta a RCE
6032026-09-04T17:58:20ZDrupalgeddon2https://github.com/dreadlocked/Drupalgeddon2Exploit per Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)