370 repositorios
Demonstrations and exploit scripts for publicly disclosed software vulnerabilities.
Explore 370 awesome GitHub repositories matching part of an awesome list · Vulnerability Proofs. Refine with filters or upvote what's useful.
Este proyecto es una implementación de prueba de concepto para CVE-2026-31431, que sirve como herramienta de escalada de privilegios local para el kernel de Linux. Funciona como un exploit que permite a una cuenta de usuario estándar obtener permisos de root. La herramienta demuestra un ataque de caché de página del kernel, donde el acceso root se logra escribiendo shellcode en las páginas cacheadas de un binario privilegiado. Este proceso manipula cómo el kernel de Linux maneja las cachés de página para ejecutar código con permisos elevados. El repositorio cubre áreas de investigación de seguridad en Linux, incluyendo análisis de corrupción de memoria del kernel y pruebas de escalada de privilegios local para verificar la susceptibilidad del sistema a esta vulnerabilidad específica.
PoC for Copy Fail LPE.
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
PoC for Log4Shell JNDI injection.
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
PoC for Netfilter LPE.
PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
PoC for PetitPotam NTLM relay.
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
PoC for Log4Shell RCE.
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
PoC for noPac LPE.
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
PoC for PwnKit LPE.
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
PoC for ZeroLogon.
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
PoC for PwnKit LPE.
Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
PowerShell PoC for PrintNightmare.
This is an exploit for the CVE-2021-3156 sudo vulnerability (dubbed Baron Samedit by Qualys).
PoC for Sudo LPE.
Shellshocker - Repository of "Shellshock" Proof of Concept Code
Collection of Shellshock PoCs.
LPE exploit for CVE-2022-34918. This exploit has been written for the kernel Linux ubuntu 5.15.0-39-generic
PoC for Netfilter LPE.
CVE-2026-23631 (DarkReplica) Redis Exploit
Exploit for Redis master-replica synchronization vulnerability.
An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debugging ports on Android 13+ and establishes a fully interactive raw PTY shell.
Vulnerability research for ADB authentication bypass.