Joomla-3.4.6-RCE. Joomla 3.4.6 – Remote Code Execution
108DeepSeek-Vulnerability-Analyzer. Python
92ClamAV_0Day_exploit. ClamAV_0Day_exploit
90TP5_Arbitrary_file_read.
50loxs-optimized. Python
45Server-2012---RCE. server2012-Group-policy-RCE
45CVE-2022-3656. HTML
38Online-Crawler-Wayback-Machine. Online-Crawler-Wayback-Machine
27Automated_Incloud_Scan.
20CVE-2020-16898-exp. Python
17Oracle-E-Business_Login.
17Burp-Rxss-scan-TG. Python
14CVE-2024-3400. Python
13CVE-2024-21006.
12AutoPWN-Suite. AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.
4Ajenti-RCE. Ajenti-RCE
4web-check. 🕵️♂️ All-in-one OSINT tool for analysing any website
4fuzzing-templates. Community curated list of nuclei templates for finding "unknown" security vulnerabilities.
3fuzz4bounty. 1337 Wordlists for Bug Bounty Hunting
3maigret. 🕵️♂️ Collect a dossier on a person by username from thousands of sites
3CVE-2024-6387. SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems
3afrog. A Security Tool for Bug Bounty, Pentest and Red Teaming.
3CVE-2024-29973.
3One-Liners. A collection of awesome one-liners for bug bounty hunting.
3nuclei_poc. Nuclei POC,每日更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现(已有11wPOC,已校验有效性并去重)
20day-RCE-exploit-on-vBulletin-5xx. https://twitter.com/momika233
2SocksOverRDP. Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop
2CVE-2023-48788. Fortinet FortiClient EMS SQL Injection
2WayBackupFinder. A passive way to find backups/ sensitive information.
2jwt-cracker. Simple HS256, HS384 & HS512 JWT token brute force cracker.
2Filter-Nuclei_poc. https://x.com/momika233
2LostXtools. Python
2njRAT.
2cent. A collection of Nuclei templates
1AdaptixC2. C
1SqlmapXPlus. SqlmapXPlus 基于 sqlmap,对经典的数据库漏洞利用工具进行二开!
1WannaCry. 基于C#编写的WannaCry模拟病毒,通常应用于网络安全应急演练
1Packer-Fuzzer. Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.
1PeiQi-WIKI-Book. 面向网络安全从业者的知识文库🍃
1sniffnet. Comfortably monitor your Internet traffic 🕵️♂️
1HackBrowserData. Decrypt passwords/cookies/history/bookmarks from the browser. 一款可全平台运行的浏览器数据导出解密工具。
1my-oneliners. Python
1can-i-take-over-xyz. "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
1momika233.
1CVE-2022-27666. Exploit for CVE-2022-27666
1chaospy. Small Tool written based on chaos from projectdiscovery.io
1keyhacks. Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
1EDR-XDR-AV-Killer. Reproducing Spyboy technique, which involves terminating all EDR/XDR/AVs processes by abusing the zam64.sys driver
1CVE-2024-21887. A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
1BinarySpy. 一个手动或自动patch shellcode到二进制文件的免杀工具/A tool for manual or automatic patch shellcode into binary file oder to bypass AV.
1WechatBot. 一个基于✨HOOK机制的微信机器人,支持🌱安全新闻定时推送【FreeBuf,先知,安全客,奇安信攻防社区】,👯Kfc文案,⚡备案查询,⚡手机号归属地查询,⚡WHOIS信息查询,🎉星座查询,⚡天气查询,🌱摸鱼日历,⚡微步威胁情报查询, 🐛美女视频,⚡美女图片,👯帮助菜单。📫 支持积分功能,⚡支持自动拉人,⚡检测广告,🌱自动群发,👯Ai回复,😄自定义程度丰富,小白也可轻松上手!
1GoogleRecaptchaBypass. Solve Google reCAPTCHA in less than 5 seconds! 🚀
1orbitaldump. A simple multi-threaded distributed SSH brute-forcing tool written in Python
1ityfuzz. Blazing Fast Bytecode-Level Hybrid Fuzzer for Smart Contracts
1CVE-2024-23108. CVE-2024-23108: Fortinet FortiSIEM Unauthenticated 2nd Order Command Injection
1SSH-Snake. SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.
1yarb. 方便获取每日安全资讯的爬虫和推送程序
1github-dorks. Find leaked secrets via github search
1dvenom. 🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.
1hacker. HTML
1