Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/ghosttroops/top
权限提升漏洞分析漏洞利用Web应用程序漏洞利用渗透测试红队精选资源
GitHubghosttroops/top

TOP

TOP 所有 bugbounty 渗透测试 CVE-2023- POC Exp RCE 示例 payload 内容

查看仓库
7311286911小时53分前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

Tweet Follow on Twitter GitHub Followers Top Langs

TOP

所有 Top Top Top_Codeql TOP 所有 bugbounty 渗透测试 CVE-2022- POC Exp 内容

目录

  • 2026 年 top 总计 30
  • 2025 年 top 总计 30
  • 2024 年 top 总计 30
  • 2023 年 top 总计 30
  • 2022 年 top 总计 30
  • 2021 年 top 总计 30
  • 2020 年 top 总计 30
  • 2019 年 top 总计 30
  • 2018 年 top 总计 30

2026

2025

2024

2022

2021

2020

2018

2017

捐赠

微信支付支付宝PaypalBTC PayBCH Pay
paypal [email protected]
下载工具
starupdated_atnameurldes
40602026-09-05T18:54:27Zcopy-fail-CVE-2026-31431https://github.com/theori-io/copy-fail-CVE-2026-31431Copy Fail (CVE-2026-31431):由 Theori 的 Xint Code 发现的 9 年前 Linux 内核本地提权漏洞
9162026-09-02T14:29:52Zwp2shell-PoChttps://github.com/sowarma/wp2shell-PoCCVE-2026-63030 与 CVE-2026-60137 RCE 利用链概念验证
7722026-09-05T23:36:29Zwp2shell-pochttps://github.com/Icex0/wp2shell-pocwp2shell (CVE-2026-63030 与 CVE-2026-60137) - 完整 RCE 利用链
1812026-08-20T10:42:34Znext-16.2.4-pocshttps://github.com/dwisiswant0/next-16.2.4-pocsNext.js v16.2.4 安全 PoC 合集 (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572)
9332026-09-05T19:06:56ZBYOVDhttps://github.com/BlackSnufkin/BYOVDBYOVD 研究用例,包含易受攻击驱动程序的发现与逆向工程方法论。(CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501)。
5722026-09-04T17:20:17Zcve_2026_31431https://github.com/rootsecdev/cve_2026_31431CVE_2026_31431 的漏洞利用 POC
7392026-09-06T02:36:18Zghostlock-apphttps://github.com/YuKongA/ghostlock-appGhostLock 一键执行应用 (CVE-2026-43499)
3262026-09-03T07:37:39ZCVE-2026-54121https://github.com/aniqfakhrul/CVE-2026-54121Certighost POC
5322026-09-03T19:17:51Zcve-2026-41940-PoChttps://github.com/lanicer/cve-2026-41940-PoC一个 cPanel 和 WHM 身份验证绕过工具
2392026-09-05T22:29:13ZCVE-2026-43499-popsiclehttps://github.com/x-spy/CVE-2026-43499-popsicle针对 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k 的 CVE-2026-43499 实现
2122026-08-24T15:13:49ZCVE-2026-41089https://github.com/0xABCD01/CVE-2026-41089CVE-2026-41089 PoC — Netlogon CLDAP 栈缓冲区溢出 (CVSS 9.8 严重)
2592026-09-02T02:28:06ZCVE-2026-21858https://github.com/Chocapikk/CVE-2026-21858n8n Ni8mare - 未认证任意文件读取到 RCE 利用链 (CVSS 10.0)
11132026-09-06T01:24:04ZRoot-My-Galaxyhttps://github.com/BuSung-dev/Root-My-Galaxy适用于受支持三星 Galaxy 固件的 KSU 安装器,利用 CVE-2026-43499
2622026-08-30T07:08:06ZCVE-2026-40369-EXPLOIThttps://github.com/orinimron123/CVE-2026-40369-EXPLOITCVE-2026-40369 的完整漏洞利用代码 - 一个 Windows 内核任意写入漏洞,可从所有浏览器的渲染进程沙箱逃逸浏览器沙箱
2072026-09-03T10:13:28ZCVE-2026-24061https://github.com/SafeBreach-Labs/CVE-2026-24061CVE-2026-24061 的漏洞利用
1562026-09-05T22:29:10ZCVE-2026-43499https://github.com/MobiusM/CVE-2026-43499CVE-2026-43499 PoC
3612026-08-31T10:04:28Zcopyfail-gohttps://github.com/badsectorlabs/copyfail-gocopyfail (CVE-2026-31431) 的 Go 实现
1742026-09-04T12:54:40ZCVE-2026-62911https://github.com/hypnguyen1209/CVE-2026-62911Exchange 上的预认证 RCE POC
1062026-09-02T14:50:34Zwp2shellhttps://github.com/0xsha/wp2shellCVE-2026-63030 + CVE-2026-60137 - “wp2shell”:WordPress 核心中的未认证 RCE
8242026-08-29T02:46:00ZCVE-2026-24061https://github.com/jacubes/CVE-2026-24061CVE-2026-24061 漏洞利用 PoC
4962026-09-04T11:37:28ZcPanelSniperhttps://github.com/ynsmroztas/cPanelSniperCVE-2026-41940 — 通过会话文件 CRLF 注入的 cPanel 和 WHM 身份验证绕过
882026-09-05T14:30:39ZCVE-2026-75604-pochttps://github.com/rafabd1/CVE-2026-75604-pocCVE-2026-75604 Next.js Windows RCE poc
2122026-09-05T15:31:02ZResetNightmarehttps://github.com/Semperis-Community/ResetNightmareResetNightmare (CVE-2026-27912) 的 POC 工具
1282026-08-19T06:30:54ZCVE-2026-20817https://github.com/oxfemale/CVE-2026-20817Windows 错误报告 ALPC 权限提升 (CVE-2026-20817) - 演示通过 WER 服务进行本地权限提升的概念验证漏洞利用。
3172026-09-06T01:32:07ZRoot-My-Pixelhttps://github.com/alex193a/Root-My-Pixel利用 CVE-2026-43499 越狱受支持的 Google Pixel 手机
1012026-09-04T19:55:40ZCVE-2026-42980-POChttps://github.com/G4sp4rCS/CVE-2026-42980-POCCVE-2026-42980 公开漏洞利用 + 研究
462026-09-03T14:49:43Zsamsung-android-lpehttps://github.com/Vikramaditya015/samsung-android-lpeCVE-2026-20980、CVE-2026-20981、CVE-2026-20982 的 Poc
612026-09-05T16:57:13Zwp2shell-scannerhttps://github.com/ZephrFish/wp2shell-scannerCVE-2026-63030、CVE-2026-60137、wp2shell 扫描器
1112026-08-30T13:42:25ZCVE-2026-31431-Advanced-Exploithttps://github.com/Sndav/CVE-2026-31431-Advanced-ExploitCVE-2026-31431 纯文件利用
1202026-09-03T20:31:36ZCVE-2026-41651https://github.com/Vozec/CVE-2026-41651
starupdated_atnameurldes
14312026-09-01T11:54:27ZCVE-2025-55182https://github.com/msanft/CVE-2025-55182CVE-2025-55182 的说明与完整 RCE PoC
24582026-09-05T16:31:41Zreact2shell-scannerhttps://github.com/assetnote/react2shell-scanner针对 RSC/Next.js RCE 的高保真检测机制 (CVE-2025-55182 与 CVE-2025-66478)
7932026-08-24T12:23:34ZCVE-2025-55182-researchhttps://github.com/ejpir/CVE-2025-55182-researchCVE-2025-55182 POC
4932026-08-11T09:12:24ZCVE-2018-20250https://github.com/WyAtu/CVE-2018-20250针对 https://research.checkpoint.com/extracting-code-execution-from-winrar 的 exp
7162026-09-02T03:40:10ZCVE-2025-33073https://github.com/mverschu/CVE-2025-33073NTLM 反射 SMB 漏洞的 PoC 漏洞利用。
9332026-09-05T19:06:56ZBYOVDhttps://github.com/BlackSnufkin/BYOVDBYOVD 研究用例,包含易受攻击驱动程序的发现与逆向工程方法论。(CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501)。
5302026-08-30T23:03:21ZCVE-2025-32463_chwoothttps://github.com/pr0v3rbs/CVE-2025-32463_chwoot通过带 chroot 选项的 sudo 二进制文件提升至 root 权限。CVE-2025-32463
2502026-08-23T00:40:02ZIngressNightmare-PoChttps://github.com/hakaioffsec/IngressNightmare-PoC这是一个用于利用 IngressNightmare 漏洞 (CVE-2025-1097、CVE-2025-1098、CVE-2025-24514 和 CVE-2025-1974) 的 PoC 代码。
3442026-08-24T14:52:54Zredis_exploithttps://github.com/raminfp/redis_exploitCVE-2025-49844 (RediShell)
4762026-09-05T19:01:51ZCVE-2025-32463https://github.com/kh4sh3i/CVE-2025-32463通过 Linux 中的 Sudo chroot 进行本地权限提升至 Root
2682026-08-24T14:52:49ZCVE-2025-48799https://github.com/Wh04m1001/CVE-2025-48799
3152026-08-15T22:24:28ZCVE-2025-53770-Exploithttps://github.com/soltanali0/CVE-2025-53770-ExploitSharePoint WebPart 注入漏洞利用工具
1422026-08-14T00:51:12ZNextjs_RCE_Exploit_Toolhttps://github.com/pyroxenites/Nextjs_RCE_Exploit_Tool针对 CVE-2025-55182 与 CVE-2025-66478 的漏洞利用
3162026-08-29T00:10:14ZCVE-2025-55182https://github.com/emredavut/CVE-2025-55182RSC/Next.js RCE 漏洞检测器与 PoC Chrome 扩展 – CVE-2025-55182 与 CVE-2025-66478
10582026-08-29T11:37:43ZReact2Shell-CVE-2025-55182-original-pochttps://github.com/lachlan2k/React2Shell-CVE-2025-55182-original-pocReact2Shell CVE-2025-55182 的原始概念验证
4082026-09-04T04:29:58ZCVE-2025-24071_PoChttps://github.com/0x6rss/CVE-2025-24071_PoCCVE-2025-24071:通过 RAR/ZIP 解压和 .library-ms 文件泄露 NTLM 哈希
1642026-07-15T09:04:59ZAirBorne-PoChttps://github.com/ekomsSavior/AirBorne-PoCCVE-2025-24252 与 CVE-2025-24132 的 poc
1982026-08-06T15:21:14ZCVE-2025-21298https://github.com/ynwarcs/CVE-2025-21298CVE-2025-21298 的概念验证与详细信息
2152026-08-17T06:27:29ZCVE-2025-32023https://github.com/leesh3288/CVE-2025-32023CVE-2025-32023 / PlaidCTF 2025 “Zerodeo” 的 PoC 与漏洞利用
2022026-09-02T23:45:49ZiOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201CVE-2025-31200 是 iOS CoreAudio 的 AudioConverterService 中的一个零日、零点击 RCE,通过 iMessage/SMS 发送的恶意音频文件触发。该漏洞利用绕过了 Blastdoor,实现了内核提权 (CVE-2025-31201),并允许令牌窃取,直到在 iOS 18.4.1 (2025 年 4 月 16 日) 中修复。
1962026-07-20T18:42:16ZCVE-2025-30208-EXPhttps://github.com/ThumpBo/CVE-2025-30208-EXPCVE-2025-30208-EXP
1902026-03-25T19:46:42ZRSC-Detect-CVE-2025-55182https://github.com/alptexans/RSC-Detect-CVE-2025-55182RSC Detect CVE 2025 55182
3852026-08-11T06:04:12ZColorOS-CVE-2025-10184https://github.com/yuuouu/ColorOS-CVE-2025-10184ColorOS短信漏洞,以及用户自救方案
2832026-08-31T11:32:54ZCVE-2025-55182-advanced-scanner-https://github.com/zack0x01/CVE-2025-55182-advanced-scanner-
4322026-08-30T22:41:40ZNext.js-RSC-RCE-Scanner-CVE-2025-66478https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478一个用于批量检测 Next.js 应用程序版本并判断其是否受 CVE-2025-66478 漏洞影响的命令行扫描器。
1972026-08-27T11:19:26ZPOC-CVE-2025-24813https://github.com/absholi7ly/POC-CVE-2025-24813该仓库包含一个自动化概念验证 (PoC) 脚本,用于利用 CVE-2025-24813,这是 Apache Tomcat 中的一个远程代码执行 (RCE) 漏洞。该漏洞允许攻击者将恶意序列化载荷上传到服务器,在满足特定条件时通过反序列化导致任意代码执行。
1512026-07-23T05:00:18ZCVE-2025-11001https://github.com/pacbypass/CVE-2025-11001针对 CVE-2025-11001 或 CVE-2025-11002 的漏洞利用
912026-08-03T04:47:49ZIngressNightmare-POCshttps://github.com/sandumjacob/IngressNightmare-POCsCVE-2025-1974
2322026-09-03T19:51:55ZCVE-2025-21333-POChttps://github.com/MrAle98/CVE-2025-21333-POC针对 CVE-2025-21333 基于堆的缓冲区溢出的 POC 漏洞利用。它利用 WNF 状态数据和 I/O 环 IOP_MC_BUFFER_ENTRY
3542026-08-25T14:17:44Zo3_finds_cve-2025-37899https://github.com/SeanHeelan/o3_finds_cve-2025-37899关于使用 o3 发现 CVE-2025-37899 的博客文章相关材料
starupdated_atnameurldes
24582026-09-01T15:26:46ZCVE-2024-1086https://github.com/Notselwyn/CVE-2024-1086针对 CVE-2024-1086 的通用本地权限提升概念验证漏洞利用,适用于 v5.14 至 v6.6 之间的大多数 Linux 内核,包括 Debian、Ubuntu 和 KernelCTF。在 KernelCTF 镜像中成功率为 99.4%。
6922026-09-01T03:08:23ZCVE-2024-38063https://github.com/ynwarcs/CVE-2024-38063CVE-2024-38063 的 poc (tcpip.sys 中的 RCE)
4972026-09-04T20:23:59Zcve-2024-6387-pochttps://github.com/zgzhang/cve-2024-6387-pocOpenSSH 服务器 (sshd) 中的信号处理程序竞态条件
5202026-08-21T18:07:43ZCVE-2024-49113https://github.com/SafeBreach-Labs/CVE-2024-49113LdapNightmare 是一个 PoC 工具,用于针对 CVE-2024-49113 测试易受攻击的 Windows Server
5332026-07-10T06:04:54Zgit_rcehttps://github.com/amalmurali47/git_rceCVE-2024-32002 的漏洞利用 PoC
5282026-09-02T11:37:54ZCVE-2024-6387_Checkhttps://github.com/xaitax/CVE-2024-6387_CheckCVE-2024-6387_Check 是一个轻量、高效的工具,旨在识别运行易受攻击 OpenSSH 版本的服务器
2242026-08-24T14:52:32ZCVE-2024-38077https://github.com/qi4L/CVE-2024-38077RDL 的堆溢出导致的 RCE
3352026-08-15T23:13:07ZCVE-2024-21338https://github.com/hakaioffsec/CVE-2024-21338在启用 HVCI 的 Windows 10 和 Windows 11 操作系统上,从 Admin 到 Kernel 的本地权限提升漏洞。
3782026-09-02T00:38:43Zcve-2024-6387-pochttps://github.com/acrono/cve-2024-6387-pocCVE-2024-6387 的 32 位 PoC — 原始 7etsuo/cve-2024-6387-poc 的镜像
3302026-08-12T11:23:08ZCVE-2024-0044https://github.com/0xbinder/CVE-2024-0044CVE-2024-0044:一个影响 Android 12 和 13 版本的“以任意应用身份运行”高危漏洞
3222026-09-03T14:04:19ZCVE-2024-4577https://github.com/watchtowrlabs/CVE-2024-4577PHP CGI 参数注入 (CVE-2024-4577) 远程代码执行 PoC
1352026-08-18T13:26:58Zapache-vulnerability-testinghttps://github.com/mrmtwoj/apache-vulnerability-testingApache HTTP Server 漏洞测试工具
2892026-08-15T23:13:15ZCVE-2024-30088https://github.com/tykawaii98/CVE-2024-30088
2802026-09-03T06:39:26ZCVE-2024-21413https://github.com/CMNatic/CVE-2024-21413用于 THM 实验的 CVE-2024-21413 PoC
35532026-09-03T02:30:53Zxzbothttps://github.com/amlweems/xzbotxz 后门 (CVE-2024-3094) 的笔记、蜜罐和漏洞利用演示
2072026-08-06T10:48:24ZCVE-2024-23897https://github.com/h4x0r-dz/CVE-2024-23897CVE-2024-23897
7702026-09-03T01:08:20ZCVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerabilityhttps://github.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-VulnerabilityMicrosoft-Outlook-远程代码执行漏洞
2032026-08-31T10:28:00ZCVE-2024-4367-PoChttps://github.com/LOURC0D3/CVE-2024-4367-PoCCVE-2024-4367 与 CVE-2024-34342 概念验证
2712026-08-28T14:55:35ZCVE-2024-49138-POChttps://github.com/MrAle98/CVE-2024-49138-POCCVE-2024-49138 的 POC 漏洞利用
1942026-08-29T10:01:47ZCVE-2024-6387https://github.com/Karmakstylez/CVE-2024-6387OpenSSH 服务器中的远程未认证代码执行漏洞 (CVE-2024-6387)
92026-08-15T23:13:20ZCVE-2024-38077-POChttps://github.com/SecStarBot/CVE-2024-38077-POC
2352026-07-27T12:00:41ZCVE_2024_30078_POC_WIFIhttps://github.com/blkph0x/CVE_2024_30078_POC_WIFI最新 Windows WiFi 驱动程序 CVE 的基本概念
1802026-08-10T14:45:08ZCVE-2024-25600https://github.com/Chocapikk/CVE-2024-25600未认证远程代码执行 – Bricks <= 1.9.6
2172026-08-22T03:10:54ZCVE-2024-21111https://github.com/mansk1es/CVE-2024-21111Oracle VirtualBox 权限提升 (本地权限提升) 漏洞
1362026-08-15T23:13:25ZCVE-2024-7479_CVE-2024-7481https://github.com/PeterGabaldon/CVE-2024-7479_CVE-2024-7481TeamViewer 用户到内核权限提升 PoC。CVE-2024-7479 和 CVE-2024-7481。ZDI-24-1289 和 ZDI-24-1290。TV-2024-1006。
1472026-08-10T13:29:55ZCVE-2024-38200https://github.com/passtheticket/CVE-2024-38200CVE-2024-38200 与 CVE-2024-43609 - Microsoft Office NTLMv2 信息泄露漏洞
812026-07-27T12:00:40ZCVE-2024-30078-https://github.com/lvyitian/CVE-2024-30078-CVE-2024-30078 检测与命令执行脚本
872026-08-15T22:24:27ZCVE-2024-40725-CVE-2024-40898https://github.com/TAM-K592/CVE-2024-40725-CVE-2024-40898CVE-2024-40725 和 CVE-2024-40898,影响 Apache HTTP Server 2.4.0 至 2.4.61 版本。这些缺陷对全球 Web 服务器构成重大风险,可能导致源代码泄露和服务器端请求伪造 (SSRF) 攻击。
1122026-08-30T11:11:36ZCVE-2024-6387https://github.com/l0n3m4n/CVE-2024-6387PoC - OpenSSH 服务器中的远程未认证代码执行漏洞 (扫描器与漏洞利用)
1582026-08-24T03:27:37ZCVE-2024-21413https://github.com/duy-31/CVE-2024-21413Microsoft Outlook 信息泄露漏洞 (泄露密码哈希) - Expect 脚本 POC
starupdated_atnameurldes
---------------
4192026-07-27T12:00:10Zqq-tim-elevationhttps://github.com/vi3t1/qq-tim-elevationCVE-2023-34312
14892026-09-01T15:26:22Zcvelisthttps://github.com/CVEProject/cvelist通过 GitHub 提交 CVE 的试点项目。通过试点 PR 提交 CVE 记录,截止日期为 2023/6/30
5062026-08-21T11:19:59ZWindows_LPE_AFD_CVE-2023-21768https://github.com/chompie1337/Windows_LPE_AFD_CVE-2023-21768CVE-2023-21768 的本地提权漏洞利用
7822026-07-29T17:11:08ZCVE-2023-38831-winrar-exploithttps://github.com/b1tg/CVE-2023-38831-winrar-exploitCVE-2023-38831 WinRAR 漏洞利用生成器
3832026-09-05T06:31:33ZCVE-2023-32233https://github.com/Liuk3r/CVE-2023-32233CVE-2023-32233:Linux内核中的安全漏洞
3942026-09-05T21:48:15ZCVE-2023-4911https://github.com/leesh3288/CVE-2023-4911CVE-2023-4911 的概念验证
4182026-07-27T12:00:05ZCVE-2023-0386https://github.com/xkaneiki/CVE-2023-0386CVE-2023-0386在ubuntu22.04上的提权
1162026-08-24T14:52:11ZCVE-2023-21839https://github.com/ASkyeye/CVE-2023-21839Weblogic CVE-2023-21839 远程代码执行(无需Java依赖一键RCE)
3282026-08-18T21:26:43ZCVE-2023-21752https://github.com/Wh04m1001/CVE-2023-21752
6522026-09-05T14:40:10Zkeepass-password-dumperhttps://github.com/vdohney/keepass-password-dumperCVE-2023-32784 的原始概念验证
2832026-07-30T00:43:58ZCVE-2023-21608https://github.com/hacksysteam/CVE-2023-21608Adobe Acrobat Reader - CVE-2023-21608 - 远程代码执行漏洞利用
3172026-08-20T20:28:38ZCVE-2023-4863https://github.com/mistymntncop/CVE-2023-4863
2422026-08-21T11:20:13ZCVE-2023-36874https://github.com/Wh04m1001/CVE-2023-36874
2472026-08-14T12:24:08ZCVE-2023-44487https://github.com/bcdannyboy/CVE-2023-44487基础漏洞扫描,用于检测 Web 服务器是否可能受 CVE-2023-44487 影响
2282026-07-29T15:55:14ZCVE-2023-3519https://github.com/BishopFox/CVE-2023-3519CVE-2023-3519 的远程代码执行漏洞利用
2452026-08-10T14:45:02ZCVE-2023-7028https://github.com/Vozec/CVE-2023-7028本仓库展示了 CVE-2023-7028 的概念验证
1692026-07-12T21:14:55ZCVE-2023-36745https://github.com/N1k0la-T/CVE-2023-36745
1402026-08-09T23:29:11ZCVE-2023-34362https://github.com/horizon3ai/CVE-2023-34362MOVEit CVE-2023-34362
2282026-08-25T15:16:27ZCVE-2023-20887https://github.com/sinsinology/CVE-2023-20887VMWare vRealize Network Insight 预认证远程代码执行(CVE-2023-20887)
3452026-09-03T19:51:33ZCVE-2023-23397-POC-Powershellhttps://github.com/api0cradle/CVE-2023-23397-POC-Powershell
1832026-08-15T23:12:53ZCVE-2023-28252https://github.com/fortra/CVE-2023-28252
1362026-08-15T22:24:27ZCVE-2023-2640-CVE-2023-32629https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629GameOver(lay) Ubuntu 权限提升
2892026-08-08T13:06:40ZCVE-2023-25690-POChttps://github.com/dhmosfunk/CVE-2023-25690-POCCVE 2023 25690 概念验证 - Apache HTTP Server 2.4.0 - 2.4.55 版本中 mod_proxy 的易受攻击配置会导致 HTTP 请求走私漏洞。
2412026-08-06T11:26:50ZWeblogic-CVE-2023-21839https://github.com/DXask88MA/Weblogic-CVE-2023-21839
2062026-08-31T13:38:48ZCVE-2023-46747-RCEhttps://github.com/W01fh4cker/CVE-2023-46747-RCE针对 f5-big-ip 远程代码执行漏洞 cve-2023-46747 的利用
1532026-09-04T10:06:50Zcve-2023-29360https://github.com/Nero22k/cve-2023-29360针对 MSKSSRV.SYS 驱动程序的 CVE-2023-29360 漏洞利用
2372026-09-03T19:51:42ZCVE-2023-29357https://github.com/Chocapikk/CVE-2023-29357Microsoft SharePoint Server 权限提升漏洞
1672026-08-17T13:31:52ZCVE-2023-25157https://github.com/win3zz/CVE-2023-25157CVE-2023-25157 - GeoServer SQL 注入 - 概念验证
1652026-07-23T03:14:23ZWindows_MSKSSRV_LPE_CVE-2023-36802https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802CVE-2023-36802 的本地提权漏洞利用
1582026-08-21T11:20:01ZCVE-2023-23397_EXPLOIT_0DAYhttps://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAYCVE-2023-23397 的漏洞利用
starupdated_atnameurldes
4382026-09-05T06:31:04ZCVE-2022-25636https://github.com/Bonfee/CVE-2022-25636CVE-2022-25636
4612026-08-28T14:55:07ZCVE-2022-21882https://github.com/KaLendsi/CVE-2022-21882win32k 本地提权
11332026-08-26T03:57:20ZCVE-2022-0847-DirtyPipe-Exploithttps://github.com/Arinerron/CVE-2022-0847-DirtyPipe-ExploitCVE-2022-0847(Dirty Pipe)的 root 提权漏洞利用
3792026-07-11T17:00:38ZCVE-2022-0185https://github.com/Crusaders-of-Rust/CVE-2022-0185CVE-2022-0185
6732026-07-23T03:14:03ZCVE-2022-29072https://github.com/kagancapar/CVE-2022-29072Windows 上 21.07 及之前版本的 7-Zip 在将 .7z 扩展名文件拖拽到 Help>Contents 区域时,允许权限提升和命令执行。
4972026-09-01T03:56:02ZCVE-2022-0995https://github.com/Bonfee/CVE-2022-0995CVE-2022-0995 漏洞利用
5732026-08-24T11:54:59ZCVE-2022-23222https://github.com/tr3ee/CVE-2022-23222CVE-2022-23222:Linux 内核 eBPF 本地权限提升
5282026-07-11T17:03:47ZOpenSSL-2022https://github.com/NCSC-NL/OpenSSL-2022关于 CVE-2022-3602 和 CVE-2022-3786(OpenSSL 3 中的两个漏洞)的操作信息
2232026-05-13T19:49:24ZSpring-Cloud-Gateway-CVE-2022-22947https://github.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947CVE-2022-22947
3602026-08-18T21:14:11ZCVE-2022-21907https://github.com/ZZ-SOCMAP/CVE-2022-21907HTTP 协议栈远程代码执行漏洞 CVE-2022-21907
3772026-08-21T11:19:25ZCVE-2022-29464https://github.com/hakivvi/CVE-2022-29464WSO2 远程代码执行(CVE-2022-29464)漏洞利用及分析文章。
7322026-09-05T06:19:39ZCVE-2022-0847-DirtyPipe-Exploitshttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits一组可用于利用 Linux Dirty Pipe 漏洞的漏洞利用代码和文档。
3582026-09-01T19:54:28ZCVE-2022-40684https://github.com/horizon3ai/CVE-2022-40684影响 Fortinet FortiOS、FortiProxy 和 FortiSwitchManager 的 CVE-2022-40684 概念验证漏洞利用
4872026-08-21T11:19:45ZCVE-2022-2588https://github.com/Markakd/CVE-2022-2588CVE-2022-2588 的漏洞利用
3872026-07-27T14:08:58ZCVE-2022-39197https://github.com/its-arun/CVE-2022-39197CobaltStrike <= 4.7.1 远程代码执行
4142026-09-03T19:51:26ZCVE-2022-33679https://github.com/Bdenneu/CVE-2022-33679基于 https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html 的 1day
2822026-06-22T01:47:59ZCVE-2022-0847https://github.com/r1is/CVE-2022-0847CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
3532026-08-20T09:45:56ZCVE-2022-21894https://github.com/Wack0/CVE-2022-21894baton drop(CVE-2022-21894):安全启动安全功能绕过漏洞
3252026-07-31T14:19:06ZSpring4Shell-POChttps://github.com/reznok/Spring4Shell-POCDocker 化的 Spring4Shell(CVE-2022-22965)概念验证应用及漏洞利用
4602026-08-24T08:16:08ZCVE-2022-27254https://github.com/nonamecoder/CVE-2022-27254本田远程无钥匙系统漏洞的概念验证(CVE-2022-27254)
3172026-06-22T11:04:03ZCVE-2022-39197-patchhttps://github.com/burpheart/CVE-2022-39197-patchCVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch.
5972026-09-05T18:21:18ZCVE-2022-38694_unlock_bootloaderhttps://github.com/TomKing062/CVE-2022-38694_unlock_bootloader这是一次性签名验证绕过。如需持久性签名验证绕过,请查看 https://github.com/TomKing062/CVE-2022-38691_38692
3022026-07-26T11:42:14ZCVE-2022-21971https://github.com/0vercl0k/CVE-2022-21971CVE-2022-21971“Windows 运行时远程代码执行漏洞”的概念验证
2652026-04-05T11:55:32ZCVE-2022-39952https://github.com/horizon3ai/CVE-2022-39952CVE-2022-39952 的概念验证
2842026-08-24T14:52:04Zcve-2022-27255https://github.com/infobyte/cve-2022-27255
2382026-08-24T14:51:59ZCVE-2022-20699https://github.com/Audiobahn/CVE-2022-20699Cisco Anyconnect VPN 未认证远程代码执行(rwx 栈)
2362026-08-31T15:38:57ZCVE-2022-30075https://github.com/aaronsvk/CVE-2022-30075Tp-Link Archer AX50 认证后远程代码执行(CVE-2022-30075)
2192026-06-02T12:40:09ZCVE-2022-34918https://github.com/veritas501/CVE-2022-34918CVE-2022-34918 netfilter nf_tables 本地提权 POC
1152026-07-03T14:59:15ZCVE-2022-22963https://github.com/dinosn/CVE-2022-22963CVE-2022-22963 概念验证
1972026-07-13T09:28:39ZCVE-2022-21882https://github.com/L4ys/CVE-2022-21882
starupdated_atnameurldes
14142026-09-01T15:26:24ZnoPachttps://github.com/cube0x0/noPacCVE-2021-42287/CVE-2021-42278 扫描器与利用工具。
20012026-09-06T00:10:43ZCVE-2021-1675https://github.com/cube0x0/CVE-2021-1675PrintNightmare CVE-2021-1675/CVE-2021-34527 的 C# 和 Impacket 实现
20482026-09-01T15:26:33ZCVE-2021-4034https://github.com/berdav/CVE-2021-4034CVE-2021-4034 1day
18082026-09-05T22:53:02ZCVE-2021-40444https://github.com/lockedbyte/CVE-2021-40444CVE-2021-40444 概念验证
11622026-09-05T06:04:24ZCVE-2021-4034https://github.com/arthepsy/CVE-2021-4034PwnKit 的概念验证:polkit 的 pkexec 中的本地权限提升漏洞(CVE-2021-4034)
10232026-09-05T05:48:21ZCVE-2021-3156https://github.com/blasty/CVE-2021-3156
11082026-09-04T02:10:14ZCVE-2021-1675https://github.com/calebstewart/CVE-2021-1675CVE-2021-1675 Print Spooler 本地权限提升(PrintNightmare)的纯 PowerShell 实现
4972026-09-03T19:51:00ZCVE-2021-21972https://github.com/NS-Sp4ce/CVE-2021-21972CVE-2021-21972 漏洞利用
10672026-08-23T03:16:37Zsam-the-adminhttps://github.com/safebuffer/sam-the-admin利用 CVE-2021-42278 和 CVE-2021-42287 从普通域用户冒充域管理员
8042026-08-26T08:10:59ZCVE-2021-3156https://github.com/worawit/CVE-2021-3156Sudo Baron Samedit 漏洞利用
8332026-09-03T02:54:08ZCVE-2021-40444https://github.com/klezVirus/CVE-2021-40444CVE-2021-40444 - 完全武器化的 Microsoft Office Word 远程代码执行漏洞利用
4262026-08-23T20:16:03ZCVE-2021-1732-Exploithttps://github.com/KaLendsi/CVE-2021-1732-ExploitCVE-2021-1732 漏洞利用
10232026-09-05T23:38:24ZnoPachttps://github.com/Ridter/noPac利用 CVE-2021-42278 和 CVE-2021-42287 从普通域用户冒充域管理员
8272026-07-31T15:53:30ZCVE-2021-31166https://github.com/0vercl0k/CVE-2021-31166CVE-2021-31166 的概念验证,这是一个可远程触发的 HTTP.sys 释放后使用漏洞。
8602026-08-17T13:31:50ZCVE-2021-44228-Scannerhttps://github.com/logpresso/CVE-2021-44228-Scanner针对 Log4j2 CVE-2021-44228 的漏洞扫描器和缓解补丁
18482026-09-04T08:37:46Zlog4j-shell-pochttps://github.com/kozmer/log4j-shell-pocCVE-2021-44228 漏洞的概念验证。
11412026-08-30T16:31:59Zlog4shell-vulnerable-apphttps://github.com/christophetd/log4shell-vulnerable-app易受 Log4Shell(CVE-2021-44228)攻击的 Spring Boot Web 应用。
4432026-09-03T09:48:19ZCVE-2021-3493https://github.com/briskets/CVE-2021-3493Ubuntu OverlayFS 本地提权
3252026-05-31T05:04:48ZCVE-2021-1675-LPEhttps://github.com/hlldz/CVE-2021-1675-LPECVE-2021-1675/CVE-2021-34527 的本地权限提升版本
1862026-07-17T09:01:22Zexprologhttps://github.com/herwonowr/exprologProxyLogon 完整漏洞利用链概念验证(CVE-2021–26855、CVE-2021–26857、CVE-2021–26858、CVE-2021–27065)
4392026-06-20T15:36:09Zlog4j-finderhttps://github.com/fox-it/log4j-finder在磁盘以及 Java 归档文件中查找易受攻击的 Log4j2 版本(Log4Shell CVE-2021-44228、CVE-2021-45046、CVE-2021-45105)
4292026-07-29T10:34:22ZCVE-2021-3156https://github.com/stong/CVE-2021-3156CVE-2021-3156(sudo 堆溢出)的概念验证
1762026-08-17T13:31:49ZProxyVulnshttps://github.com/hosch3n/ProxyVulns[ProxyLogon] CVE-2021-26855 与 CVE-2021-27065 修复 RawIdentity Bug 漏洞利用。[ProxyOracle] CVE-2021-31195 与 CVE-2021-31196 漏洞利用链。[ProxyShell] CVE-2021-34473 与 CVE-2021-34523 与 CVE-2021-31207 漏洞利用链。
2872026-08-28T07:19:34ZCVE-2021-22205https://github.com/Al1ex/CVE-2021-22205CVE-2021-22205 与 GitLab CE/EE 远程代码执行
34222026-08-24T02:07:57Zlog4j-scanhttps://github.com/fullhunt/log4j-scan一个全自动、准确且全面的扫描器,用于发现 log4j 远程代码执行漏洞 CVE-2021-44228
2682026-09-03T19:51:00ZCVE-2021-21972https://github.com/horizon3ai/CVE-2021-21972vCenter CVE-2021-21972 的概念验证漏洞利用
3012026-09-04T02:23:31ZCVE-2021-36260https://github.com/Aiminsun/CVE-2021-36260某些海康威视产品 Web 服务器中的命令注入漏洞。由于输入验证不足,攻击者可以通过发送包含恶意命令的消息来利用该漏洞发起命令注入攻击。
1472026-05-23T10:52:31ZCVE-2021-41773_CVE-2021-42013https://github.com/inbug-team/CVE-2021-41773_CVE-2021-42013CVE-2021-41773 CVE-2021-42013漏洞批量检测工具
3252026-08-21T18:45:26ZCVE-2021-34527https://github.com/JohnHammond/CVE-2021-34527
1222026-09-03T09:07:12Zproxyshellhttps://github.com/horizon3ai/proxyshellCVE-2021-34473、CVE-2021-34523 和 CVE-2021-31207 的概念验证
starupdated_atnameurldes
42892026-09-04T01:55:44Zexphubhttps://github.com/zhzyker/exphubExphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
18322026-09-01T15:26:49ZCVE-2020-1472https://github.com/bvcyber/CVE-2020-1472CVE-2020-1472 测试工具
20752026-09-01T15:26:20ZweblogicScannerhttps://github.com/0xn0ne/weblogicScannerweblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883
13592026-08-21T11:17:52ZCVE-2020-0796https://github.com/danigargu/CVE-2020-0796CVE-2020-0796 - Windows SMBv3 本地提权漏洞利用 #SMBGhost
13232026-09-03T13:04:39ZCVE-2020-1472https://github.com/dirkjanm/CVE-2020-1472Zerologon 的概念验证 - 所有研究归功于 Secura 的 Tom Tervoort
2872026-08-04T08:01:02ZCVE-2020-14882https://github.com/jas502n/CVE-2020-14882CVE-2020–14882、CVE-2020–14883
3282026-08-05T23:19:15Zcve-2020-0688https://github.com/Ridter/cve-2020-0688cve-2020-0688
7062026-09-02T23:02:20Zzerologonhttps://github.com/risksense/zerologonzerologon cve-2020-1472 的漏洞利用
7222026-09-04T16:53:43ZSMBGhosthttps://github.com/ly4k/SMBGhostCVE-2020-0796 - SMBv3 远程代码执行 的扫描器
3532026-09-04T00:17:18ZCVEAC-2020https://github.com/thesecretclub/CVEAC-2020通过模拟内存更改绕过 EasyAntiCheat 完整性检查
5712026-08-15T23:12:11ZCVE-2020-0796-RCE-POChttps://github.com/jamf/CVE-2020-0796-RCE-POCCVE-2020-0796 远程代码执行概念验证
3742025-12-23T08:30:40ZCVE-2020-5902https://github.com/jas502n/CVE-2020-5902CVE-2020-5902 BIG-IP
1332026-07-03T05:20:29ZCVE_2020_2546https://github.com/hktalent/CVE_2020_2546CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
2232026-07-29T10:34:10ZSAP_RECONhttps://github.com/chipik/SAP_RECONCVE-2020-6287、CVE-2020-6286(SAP RECON 漏洞)的概念验证
8892026-08-11T23:19:25ZCurveBallhttps://github.com/ly4k/CurveBallCVE-2020-0601 的概念验证 - Windows CryptoAPI(Crypt32.dll)
2942026-08-04T08:00:45ZCNVD-2020-10487-Tomcat-Ajp-lfi-Scannerhttps://github.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-ScannerCnvd-2020-10487 / cve-2020-1938,扫描工具
3362026-08-04T08:00:45ZCVE-2020-2551https://github.com/Y4er/CVE-2020-2551Weblogic IIOP CVE-2020-2551
2492026-05-28T08:01:05ZBlueGatehttps://github.com/ly4k/BlueGateCVE-2020-0609 与 CVE-2020-0610 - RD Gateway 远程代码执行 的概念验证(拒绝服务 + 扫描器)
3542026-08-05T23:16:25ZCVE-2020-0688https://github.com/zcgonvh/CVE-2020-0688CVE-2020-0688 的漏洞利用与检测工具
7212026-08-13T09:49:27ZCVE-2020-0787-EXP-ALL-WINDOWS-VERSIONhttps://github.com/cbwang505/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION支持所有 Windows 版本
1012026-04-03T14:54:58Zdnspooqhttps://github.com/knqyf263/dnspooqDNSpooq - dnsmasq 缓存投毒(CVE-2020-25686、CVE-2020-25684、CVE-2020-25685)
3312026-09-03T11:41:49ZCVE-2020-0796-PoChttps://github.com/eerykitty/CVE-2020-0796-PoC通过 CVE-2020-0796 触发缓冲区溢出的概念验证
3982026-08-21T13:18:39ZCVE-2020-1472https://github.com/VoidSec/CVE-2020-1472CVE-2020-1472 又名 Zerologon 的漏洞利用代码
1632026-08-04T08:00:45Zcve-2020-0688https://github.com/random-robbie/cve-2020-0688cve-2020-0688
2572026-07-29T10:33:57ZCVE-2020-0041https://github.com/bluefrostsecurity/CVE-2020-0041Android Binder 漏洞 CVE-2020-0041 的漏洞利用
4232026-08-19T17:33:57ZGhostcat-CNVD-2020-10487https://github.com/00theway/Ghostcat-CNVD-2020-10487Ghostcat 读取文件/代码执行,CNVD-2020-10487(CVE-2020-1938)
5142026-09-05T02:17:56ZCVE-2020-15368https://github.com/stong/CVE-2020-15368CVE-2020-15368,又名“如何利用易受攻击的驱动程序”
3352026-06-30T12:15:45Zchainoffoolshttps://github.com/kudelskisecurity/chainoffoolsCVE-2020-0601 的概念验证
3372026-09-03T19:45:36ZCVE-2020-0683https://github.com/padovah4ck/CVE-2020-0683CVE-2020-0683 - Windows MSI “安装程序服务”权限提升
1222026-05-17T12:43:08ZCVE-2020-11651-pochttps://github.com/jasperla/CVE-2020-11651-pocCVE-2020-11651 和 CVE-2020-11652 的概念验证漏洞利用
starupdated_atnameurldes
---------------
20752026-09-01T15:26:20ZweblogicScannerhttps://github.com/0xn0ne/weblogicScannerweblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883
42892026-09-04T01:55:44Zexphubhttps://github.com/zhzyker/exphubExphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
18322026-09-04T16:09:45Zphuip-fpizdamhttps://github.com/neex/phuip-fpizdamCVE-2019-11043 的漏洞利用程序
11822026-09-04T00:56:48ZBlueKeephttps://github.com/Ekultek/BlueKeepCVE-2019-0708 的概念验证
4962026-09-01T03:59:50ZCVE-2019-0708https://github.com/n1xbyte/CVE-2019-0708dump
6582026-07-29T10:32:54ZCVE-2019-5736-PoChttps://github.com/Frichetten/CVE-2019-5736-PoCCVE-2019-5736 的 PoC
3882026-08-04T08:00:31ZCVE-2019-0708https://github.com/k8gege/CVE-2019-07083389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)
8212026-08-18T00:34:19Zesp32_esp8266_attackshttps://github.com/Matheus-Garbelini/esp32_esp8266_attacksESP32/8266 Wi-Fi 漏洞的概念验证 (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588)
4332026-05-23T10:50:00ZCVE-2019-2725https://github.com/lufeirider/CVE-2019-2725CVE-2019-2725 命令回显
5732026-07-16T11:27:46Zcve-2019-19781https://github.com/trustedsec/cve-2019-19781这是针对 Citrix ADC (NetScaler) 漏洞发布的工具。我们之所以披露,仅仅是因为其他人已经先公开了漏洞利用代码。
3482026-07-29T10:33:39ZCOMahawkhttps://github.com/apt69/COMahawk权限提升:武器化 CVE-2019-1405 和 CVE-2019-1322
3602026-07-29T10:33:28ZCVE-2019-11510https://github.com/projectzeroindia/CVE-2019-11510Pulse Secure SSL VPN 任意文件读取漏洞利用 (CVE-2019-11510)
3672026-07-16T11:27:44ZCVE-2019-19781https://github.com/projectzeroindia/CVE-2019-19781Citrix Application Delivery Controller 和 Citrix Gateway 远程代码执行漏洞利用 [ CVE-2019-19781 ]
3332026-09-01T07:22:52ZCVE-2019-13272https://github.com/jas502n/CVE-2019-13272Linux 4.10 < 5.1.17 PTRACE_TRACEME 本地提权
6242026-07-29T10:33:33ZCVE-2019-11708https://github.com/0vercl0k/CVE-2019-11708针对 Windows 64 位系统上 Firefox 的完整漏洞利用链 (CVE-2019-11708 & CVE-2019-9810)。
1292026-07-29T10:33:01ZCVE-2019-0604https://github.com/linhlhq/CVE-2019-0604CVE-2019-0604
3742026-08-18T07:57:54ZCVE-2019-18935https://github.com/noperator/CVE-2019-18935Telerik UI for ASP.NET AJAX 中 .NET JSON 反序列化漏洞的 RCE 漏洞利用程序。
3162026-07-29T10:32:54Zcve-2019-1003000-jenkins-rce-pochttps://github.com/adamyordan/cve-2019-1003000-jenkins-rce-pocJenkins RCE 概念验证:SECURITY-1266 / CVE-2019-1003000 (Script Security)、CVE-2019-1003001 (Pipeline: Groovy)、CVE-2019-1003002 (Pipeline: Declarative)
2392026-07-29T10:33:05ZCVE-2019-0841https://github.com/rogue-kdc/CVE-2019-0841CVE-2019-0841 权限提升漏洞的 PoC 代码
2092026-08-25T09:51:16ZCVE-2019-11932https://github.com/awakened1712/CVE-2019-11932利用 libpl_droidsonroids_gif 中 decoding.c 的 DDGifSlurp 里 WhatsApp 双重释放漏洞的简单 POC
2552026-08-29T12:30:21ZCVE-2019-5786https://github.com/exodusintel/CVE-2019-5786FileReader 漏洞利用
2672026-05-13T19:46:49ZCVE-2019-11932https://github.com/dorkerdevil/CVE-2019-11932WhatsApp 双重释放漏洞利用 poc
9212026-09-01T01:54:30Zrdpscanhttps://github.com/robertdavidgraham/rdpscan针对 CVE-2019-0708 "BlueKeep" 漏洞的快速扫描器。
2932026-08-28T14:54:44Zbluekeephttps://github.com/0xeb-bp/bluekeepCVE-2019-0708 的公开成果
2492026-09-02T19:00:40ZCVE-2019-1040https://github.com/Ridter/CVE-2019-1040CVE-2019-1040 与 Exchange
6812026-07-29T10:32:53Zdirty_sockhttps://github.com/initstring/dirty_sock通过 snapd 的 Linux 权限提升漏洞利用 (CVE-2019-7304)
1662026-07-29T10:33:36ZCVE-2019-7609https://github.com/LandGrey/CVE-2019-7609通过 python2 脚本以正确方式利用 CVE-2019-7609(kibana RCE)
32025-09-14T06:41:42ZCVE-2019-0708https://github.com/victor0013/CVE-2019-0708CVE-2019-0708 RDP RCE 漏洞的扫描器 PoC
2002026-09-01T04:11:59ZCVE-2019-16098https://github.com/Barakat/CVE-2019-16098CVE-2019-16098 的本地权限提升 PoC 漏洞利用程序
2082026-07-29T10:32:58ZCVE-2019-0192https://github.com/mpgn/CVE-2019-0192通过 jmx.serviceUrl 利用不可信数据反序列化对 Apache Solr 进行 RCE
starupdated_atnameurldes
20752026-09-01T15:26:20ZweblogicScannerhttps://github.com/0xn0ne/weblogicScannerweblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883
4992026-09-02T21:00:11ZCVE-2018-8120https://github.com/rip1s/CVE-2018-8120CVE-2018-8120 Windows 本地提权漏洞利用
4932026-08-11T09:12:24ZCVE-2018-20250https://github.com/WyAtu/CVE-2018-20250https://research.checkpoint.com/extracting-code-execution-from-winrar 的漏洞利用
5342026-07-03T09:06:47ZCVE-2018-15473-Exploithttps://github.com/Rhynorater/CVE-2018-15473-Exploit用 Python 编写的 CVE-2018-15473 漏洞利用程序,支持多线程和导出格式
5582026-09-05T01:15:33ZCVE-2018-9995_dvr_credentialshttps://github.com/ezelf/CVE-2018-9995_dvr_credentials(CVE-2018-9995) 获取 DVR 凭据
3692026-07-29T10:32:50ZExchange2domainhttps://github.com/Ridter/Exchange2domainCVE-2018-8581
2532026-05-18T02:43:52ZCVE-2018-13379https://github.com/milo2012/CVE-2018-13379CVE-2018-13379
4972026-09-01T03:57:01ZCVE-2018-10933https://github.com/blacknbunny/CVE-2018-10933利用 CVE-2018-10933 (LibSSH) 无需任何凭据即可获取 shell
2702026-07-14T20:29:03ZCVE-2018-0802https://github.com/rxwx/CVE-2018-0802CVE-2018-0802(以及可选的 CVE-2017-11882)的 PoC 漏洞利用程序
3542026-08-13T09:14:55ZCVE-2018-7600https://github.com/a2u/CVE-2018-7600💀CVE-2018-7600 Drupal SA-CORE-2018-002 的概念验证
2932026-09-02T21:43:04ZCVE-2018-8120https://github.com/alpha1ab/CVE-2018-8120CVE-2018-8120 针对 Win2003 Win2008 WinXP Win7 的漏洞利用
4232026-09-02T11:17:08ZCVE-2018-8897https://github.com/can1357/CVE-2018-8897利用 CVE-2018-8897 以内核权限执行任意代码。
3312026-04-11T08:21:35ZCVE-2018-8581https://github.com/WyAtu/CVE-2018-8581CVE-2018-8581
5202026-08-16T20:26:51ZWinboxPoChttps://github.com/BasuCert/WinboxPoCWinbox 严重漏洞的概念验证 (CVE-2018-14847)
782024-08-12T19:37:50ZCVE-2018-2628https://github.com/shengqi158/CVE-2018-2628CVE-2018-2628 & CVE-2018-2893
1462026-05-13T19:46:39ZCVE-2018-13382https://github.com/milo2012/CVE-2018-13382CVE-2018-13382
1392026-07-29T10:32:13ZCVE-2018-8174_EXPhttps://github.com/Yt1g3r/CVE-2018-8174_EXPCVE-2018-8174_python
2052026-07-29T10:32:16ZCVE-2018-0296https://github.com/yassineaboukir/CVE-2018-0296用于测试 Cisco ASA 路径遍历漏洞 (CVE-2018-0296) 并提取系统信息的脚本。
1722025-12-24T02:23:23ZCVE-2018-3245https://github.com/pyn3rd/CVE-2018-3245CVE-2018-3245-PoC
3032026-06-06T17:24:23Zstruts-pwn_CVE-2018-11776https://github.com/mazen160/struts-pwn_CVE-2018-11776Apache Struts CVE-2018-11776 的漏洞利用程序
1632026-07-29T10:32:10Zcve-2018-8120https://github.com/bigric3/cve-2018-8120
1402026-09-03T04:51:18ZCVE-2018-7600https://github.com/pimps/CVE-2018-7600针对 Drupal 7 <= 7.57 CVE-2018-7600 的漏洞利用程序
3752026-09-06T01:36:10ZGDRVLoaderhttps://github.com/zer0condition/GDRVLoader使用 CVE-2018-19320 的未签名驱动加载器
1792026-07-13T11:58:32ZCVE-2018-15982_EXPhttps://github.com/Ridter/CVE-2018-15982_EXPCVE-2018-15982 的漏洞利用
1192026-08-01T13:49:38Zcve-2018-8453-exphttps://github.com/ze0r/cve-2018-8453-expcve-2018-8453 漏洞利用
1662026-07-29T10:31:41ZRTF_11882_0802https://github.com/Ridter/RTF_11882_0802CVE-2018-0802 和 CVE-2017-11882 的 PoC
1672026-07-29T10:32:12ZCVE-2018-8174-msfhttps://github.com/0x09AL/CVE-2018-8174-msfCVE-2018-8174 - VBScript 内存破坏漏洞利用。
2672026-07-29T10:32:00Zcredssphttps://github.com/preempt/credssp演示 CVE-2018-0886 的代码
1402025-11-28T04:31:10ZCVE-2018-2894https://github.com/LandGrey/CVE-2018-2894CVE-2018-2894 WebLogic 任意文件上传导致 RCE 检测脚本
6032026-09-04T17:58:20ZDrupalgeddon2https://github.com/dreadlocked/Drupalgeddon2针对 Drupal v7.x + v8.x 的漏洞利用程序 (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)