161 repositorios
Proof of concept exploits targeting vulnerabilities in web applications and plugins.
Explore 161 awesome GitHub repositories matching part of an awesome list · Web Application Exploits. Refine with filters or upvote what's useful.
Sentinel is a microservice flow control framework designed for managing traffic limits, distributed circuit breaking, and adaptive overload protection. It serves as a traffic shaping component that defines resource boundaries to regulate request flow and ensure reliability across distributed systems. The project provides a real-time monitoring dashboard for tracking resource metrics and performance bottlenecks across service clusters. It includes a visual interface for the real-time management of flow control and circuit breaking rules, allowing parameters to be updated without restarting the
Security research and testing tools for microservices.
K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili
Identifies and exploits vulnerabilities in web applications, including SQL injection and deploying web shells.
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
Vulnerable application for testing Log4j exploits.
关于ThinkPHP框架的历史漏洞分析集合
Collection of exploits for ThinkPHP framework vulnerabilities.
Redis 4.x/5.x RCE
Exploit for remote code execution via Redis misconfiguration.
Exploit for CVE-2021-3129
Collection of exploits for Laravel framework vulnerabilities.
PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR module: https://github.com/rapid7/metasploit-framework/pull/13852/commits/d1e2c75b3eafa7f62a6aba9fbe6220c8da97baa8 This PoC only create user with unauthentication permission and no more administrator permission set. This project is created only for educational purposes and cannot be used for law violation or personal gain. The author of this project is not responsible for any possible harm caused by the materials of this project. Original
Exploit for SAP remote code execution.
⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions ≤ 1.5.0).
Arbitrary file upload exploit for WordPress plugin.
Exploit for Spring Cloud Function SpEL injection.
Exploit for Apache Solr remote code execution.
Exploit for EJB-based remote code execution in application servers.
SQL injection exploit for WordPress plugin.
Exploit for Fortinet firewall remote code execution.
Time-based SQL injection exploit for WordPress plugin.
Exploit for specific application vulnerabilities.
Exploit research for cryptographic validation vulnerabilities.