一个公共概念验证漏洞利用代码和漏洞研究文章的整合存档,涵盖超过20种不同的软件目标,并经过完整性验证确保文件的一致性。

Stars

69

7 天增长

暂无数据

Fork 数

124

开放 Issue

0

开源协议

暂无数据

最近更新

2026-06-29

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

该仓库作为一个罕见的、集中式的0day及接近0day的漏洞利用代码集合,覆盖了广泛的流行软件,并通过系统性整合检查保证了跟踪文件与原始独立仓库逐字节相同。

适合谁使用

  • 研究漏洞利用技术的安全研究人员
  • 需要真实世界PoC的渗透测试人员和红队成员
  • 审计自身产品类似漏洞的软件开发人员
  • 寻求灵感或参考资料的漏洞赏金猎人

典型使用场景

  • 分析7-Zip、Firefox、Docker和Ghidra等广泛使用软件中的漏洞利用模式
  • 针对已知PoC测试安全控制(如EDR、沙箱)的有效性
  • 验证修补程序或缓解措施是否能够阻断演示的攻击链
  • 在 offensive security 培训或CTF挑战中用于教学目的

项目优势

  • 整合检查验证了12个前独立仓库共96个跟踪条目,零差异,确保文件完整性
  • 覆盖了多样化目标:解压缩工具、远程桌面、库、虚拟机、浏览器、调试器、Web应用程序等
  • 既保留了独立仓库(附原始README)又新添加了直接条目,统一管理,浏览便捷
  • 作者明确欢迎协作,并可通过GitHub Issues请求分析新软件

使用前须知

  • 原始独立仓库的元数据(星标、问题、发布版本、Git历史)未保留于此
  • PoC按原样提供,不保证在软件更新或补丁后仍能运行
  • 部分条目标注了未来日期(如2026年6月),可能造成漏洞披露时间线的困惑

README 快速开始

If you wish to collaborate/discuss with me, contact me on discord @ashdfrkl

Sharing this repo keeps me motivated to continue dropping 0-days for you all.

Open an issue if you have a specific request for software you want me to take a look at.

Exploitarium

A consolidated archive of my public proof-of-concept and vulnerability research writeups.

Most folders contain one of my former standalone PoC repos, preserved with its original README and tracked files. New research entries are added directly here as self-contained folders.

Contents

FolderSourceTracked entries
7zip-rar5-motw-chain-pocbd9533f532c1e4ee6af783b9bb49d1133c600e2c3
anydesk-printer-com-impersonation-poc7491303301093b2d40bee9dadf6b38f757ce78e04
c-ares-tcp-uaf-calc-pocdirect entry, June 24, 20267
docker-cp-copyout-destination-escaped1367b1381736d7f961ac808ce88d4e24a633adc5
firefox-smartwindow-private-url-exfil-pocdirect entry, June 24, 20263
floci-apigateway-vtl-rce-pocdirect entry, June 23, 20263
flowise-mcp-env-case-bypass-poced9fab0086674f1b16467990b33bb9299e93429e3
ffmpeg-rasc-dlta-calc-pocdirect entry, June 26, 20267
ghidra-12.1.2-rce-ace-calc-poc52dee6362990c03c0d753d074c85428824d463689
gitea-act-runner-container-options-pocf06d78fb111732f3e7737f4c07e77ef94c4b64bf4
imagemagick-gs-delegate-hijack-poc8140e8ee0ed78beaf5e8303a795b70b138f5891b5
libssh2-cve-2026-55200-pocdirect entry, June 23, 20263
libssh2-publickey-list-calc-pocdirect entry, June 25, 202610
lunar-modrinth-chain-pocffd02120708b6503f11585858ce3724872f3b7a76
mybb-limited-acp-to-admin1610e0373943c2f6562a99f917d3a3d1fdd9056d5
nghttp2-nghttpx-upgrade-queue-poison-pocdirect entry, June 26, 20263
nmap-ipv6-extlen-wrap-pocdirect entry, June 23, 20264
objdump-dlx-calc-poc7df01e4e20c7375a89e8ccf760526c52eb6ad58241
openvpn-connect-echo-script-ace-pocd2f904d9272d4388c9862131d40e32e072e85e388
php857-streambucket-soap-rce-rpocdirect entry, June 26, 20266
rustdesk-session-permission-pocsdirect entry, June 25, 202617
systeminformer-phsvc-trusted-host-lpe-pocdirect entry, June 24, 20263
vlc-vp9-reschange-crash-poc`fae

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

lopopolo
精选
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI 与机器学习AI 智能体
2,390
slvDev
精选
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI 与机器学习大语言模型
1,960
littledivy
精选
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI 与机器学习
1,482