exploit
Tracked open-source repos tagged exploit, sorted by stars.
Related topics
Topics that frequently appear alongside exploit on the same repo.
Recent risers
Repos created in the last 90 days, tagged exploit.
- #1
An an app that installs Sidestore on iOS 27, fully on-device
★ 601 - #2
CVE-2026-9830 Proof of Concept
★ 399
- #1
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
★ 29,190+123Star change over the last 7 days - #2
A collection of hacking / penetration testing resources to make you better!
★ 17,364+26Star change over the last 7 days - #3★ 13,666+20Star change over the last 7 days
- #4
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
★ 11,103+38Star change over the last 7 days - #5
List of free GPTs that doesn't require plus subscription
★ 9,703+14Star change over the last 7 days - #6
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
★ 9,034+3Star change over the last 7 days - #7
GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
★ 8,324+3Star change over the last 7 days - #8★ 8,030+11Star change over the last 7 days
- #9
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
★ 8,027+27Star change over the last 7 days - #10★ 7,708+17Star change over the last 7 days
- #11
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
★ 7,477+12Star change over the last 7 days - #12
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
★ 7,160-2Star change over the last 7 days - #13
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
★ 6,726+7Star change over the last 7 days - #14
A collection of links related to Linux kernel security and exploitation
★ 6,622+14Star change over the last 7 days - #15
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
★ 6,207+8Star change over the last 7 days - #16
An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.
★ 6,190+21Star change over the last 7 days - #17
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange
★ 5,320+2Star change over the last 7 days - #18
A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive device-activity patterns. (WhatsApp / Signal)
★ 5,104+7Star change over the last 7 days - #19
A Simple android remote administration tool using sockets. It uses java on the client side and python on the server side
★ 5,060+34Star change over the last 7 days - #20★ 4,922+2Star change over the last 7 days
- #21
CTF竞赛权威指南
★ 4,494+1Star change over the last 7 days - #22
一个攻防知识库。A knowledge base for red teaming and offensive security.
★ 4,320+9Star change over the last 7 days - #23
Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
★ 4,058+13Star change over the last 7 days - #24★ 3,779+2Star change over the last 7 days
- #25
Firmware patcher for Xiaomi routers
★ 3,425+26Star change over the last 7 days - #26
Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.
★ 3,399+6Star change over the last 7 days - #27
Interesting APT Report Collection And Some Special IOCs
★ 3,086+3Star change over the last 7 days - #28★ 2,548+3Star change over the last 7 days
- #29
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
★ 2,458+0Star change over the last 7 days - #30
RootMyTV is a user-friendly exploit for rooting/jailbreaking LG webOS smart TVs.
★ 2,431+1Star change over the last 7 days