awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

161 Repos

Awesome GitHub RepositoriesWeb Application Exploits

Proof of concept exploits targeting vulnerabilities in web applications and plugins.

Explore 161 awesome GitHub repositories matching part of an awesome list · Web Application Exploits. Refine with filters or upvote what's useful.

Awesome Web Application Exploits GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • alibaba/sentinelAvatar von alibaba

    alibaba/Sentinel

    23,126Auf GitHub ansehen↗

    Sentinel is a microservice flow control framework designed for managing traffic limits, distributed circuit breaking, and adaptive overload protection. It serves as a traffic shaping component that defines resource boundaries to regulate request flow and ensure reliability across distributed systems. The project provides a real-time monitoring dashboard for tracking resource metrics and performance bottlenecks across service clusters. It includes a visual interface for the real-time management of flow control and circuit breaking rules, allowing parameters to be updated without restarting the

    Security research and testing tools for microservices.

    Java
    Auf GitHub ansehen↗23,126
  • k8gege/k8toolsAvatar von k8gege

    k8gege/K8tools

    6,167Auf GitHub ansehen↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    Identifies and exploits vulnerabilities in web applications, including SQL injection and deploying web shells.

    PowerShell0daybrute-forcebypass
    Auf GitHub ansehen↗6,167
  • christophetd/log4shell-vulnerable-appAvatar von christophetd

    christophetd/log4shell-vulnerable-app

    1,142Auf GitHub ansehen↗

    Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

    Vulnerable application for testing Log4j exploits.

    Javalog4shell
    Auf GitHub ansehen↗1,142
  • mochazz/thinkphp-vulnAvatar von Mochazz

    Mochazz/ThinkPHP-Vuln

    1,125Auf GitHub ansehen↗

    关于ThinkPHP框架的历史漏洞分析集合

    Collection of exploits for ThinkPHP framework vulnerabilities.

    Auf GitHub ansehen↗1,125
  • ridter/redis-rceAvatar von Ridter

    Ridter/redis-rce

    978Auf GitHub ansehen↗

    Redis 4.x/5.x RCE

    Exploit for remote code execution via Redis misconfiguration.

    Python
    Auf GitHub ansehen↗978
  • rhinosecuritylabs/cvesAvatar von RhinoSecurityLabs

    RhinoSecurityLabs/CVEs

    897Auf GitHub ansehen↗

    Collection of security research and exploits.

    Python
    Auf GitHub ansehen↗897
  • ambionics/laravel-exploitsAvatar von ambionics

    ambionics/laravel-exploits

    290Auf GitHub ansehen↗

    Exploit for CVE-2021-3129

    Collection of exploits for Laravel framework vulnerabilities.

    Python
    Auf GitHub ansehen↗290
  • duc-nt/cve-2020-6287-exploitAvatar von duc-nt

    duc-nt/CVE-2020-6287-exploit

    96Auf GitHub ansehen↗

    PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR module: https://github.com/rapid7/metasploit-framework/pull/13852/commits/d1e2c75b3eafa7f62a6aba9fbe6220c8da97baa8 This PoC only create user with unauthentication permission and no more administrator permission set. This project is created only for educational purposes and cannot be used for law violation or personal gain. The author of this project is not responsible for any possible harm caused by the materials of this project. Original

    Exploit for SAP remote code execution.

    Python
    Auf GitHub ansehen↗96
  • 0nise/vuldebug0

    0nise/vuldebug

    0Auf GitHub ansehen↗

    Tools for debugging and exploiting web vulnerabilities.

    Auf GitHub ansehen↗0
  • willygailo/cve-2026-3891-linuxAvatar von willygailo

    willygailo/CVE-2026-3891-Linux

    1Auf GitHub ansehen↗

    ⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions ≤ 1.5.0).

    Arbitrary file upload exploit for WordPress plugin.

    Python
    Auf GitHub ansehen↗1
  • hieuminhnv/cve-2022-21587-pocH

    hieuminhnv/CVE-2022-21587-POC

    0Auf GitHub ansehen↗

    Expl

    Auf GitHub ansehen↗0
  • chaosec2021/spring-cloud-function-spel-rceC

    chaosec2021/Spring-cloud-function-SpEL-RCE

    0Auf GitHub ansehen↗

    Exploit for Spring Cloud Function SpEL injection.

    Auf GitHub ansehen↗0
  • redteampentesting/cve-2020-13935R

    RedTeamPentesting/CVE-2020-13935

    0Auf GitHub ansehen↗

    Exploit for Apache Solr remote code execution.

    Auf GitHub ansehen↗0
  • sh286/cve-2020-8163S

    sh286/CVE-2020-8163

    0Auf GitHub ansehen↗

    Exploit for specific framework vulnerabilities.

    Auf GitHub ansehen↗0
  • axyanzzzz/tongwebejbexploitA

    Axyanzzzz/TongWebEJBExploit

    0Auf GitHub ansehen↗

    Exploit for EJB-based remote code execution in application servers.

    Auf GitHub ansehen↗0
  • itsthalisman/cve-2026-3359-expI

    itsthalisman/cve-2026-3359-exp

    0Auf GitHub ansehen↗

    SQL injection exploit for WordPress plugin.

    Auf GitHub ansehen↗0
  • horizon3ai/cve-2022-39952H

    horizon3ai/CVE-2022-39952

    0Auf GitHub ansehen↗

    Exploit for Fortinet firewall remote code execution.

    Auf GitHub ansehen↗0
  • 4ra1n/cve-2022-325324

    4ra1n/CVE-2022-32532

    0Auf GitHub ansehen↗

    Exploit for specific application vulnerabilities.

    Auf GitHub ansehen↗0
  • deepingh0st/cve-2022-28346D

    DeEpinGh0st/CVE-2022-28346

    0Auf GitHub ansehen↗

    Exploit for specific application vulnerabilities.

    Auf GitHub ansehen↗0
  • r35tart/rediswritefileR

    r35tart/RedisWriteFile

    0Auf GitHub ansehen↗

    Tool for arbitrary file writing via Redis exploitation.

    Auf GitHub ansehen↗0
Vorherige123456…9Nächste
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Web Application Exploits