370 个仓库
Demonstrations and exploit scripts for publicly disclosed software vulnerabilities.
Explore 370 awesome GitHub repositories matching part of an awesome list · Vulnerability Proofs. Refine with filters or upvote what's useful.
该项目是 CVE-2026-31431 的概念验证实现,作为 Linux 内核的本地权限提升工具。它作为一种漏洞利用程序运行,允许标准用户帐户获取 root 权限。 该工具演示了内核页缓存攻击,通过将 Shellcode 写入特权二进制文件的缓存页面来获得 root 访问权限。此过程操纵 Linux 内核处理页缓存的方式,以提升权限执行代码。 该仓库涵盖了 Linux 安全研究领域,包括内核内存损坏分析和本地权限提升测试,以验证系统对该特定漏洞的易感性。
PoC for Copy Fail LPE.
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
PoC for Log4Shell JNDI injection.
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
PoC for Netfilter LPE.
PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
PoC for PetitPotam NTLM relay.
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
PoC for Log4Shell RCE.
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
PoC for noPac LPE.
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
PoC for PwnKit LPE.
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
PoC for ZeroLogon.
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
PoC for PwnKit LPE.
Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
PowerShell PoC for PrintNightmare.
This is an exploit for the CVE-2021-3156 sudo vulnerability (dubbed Baron Samedit by Qualys).
PoC for Sudo LPE.
Shellshocker - Repository of "Shellshock" Proof of Concept Code
Collection of Shellshock PoCs.
poc it like it's hot
Collection of various security PoCs.
CVE-2023-32233: Linux内核中的安全漏洞
PoC for Netfilter LPE.
LPE exploit for CVE-2022-34918. This exploit has been written for the kernel Linux ubuntu 5.15.0-39-generic
PoC for Netfilter LPE.
CVE-2026-23631 (DarkReplica) Redis Exploit
Exploit for Redis master-replica synchronization vulnerability.
An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debugging ports on Android 13+ and establishes a fully interactive raw PTY shell.
Vulnerability research for ADB authentication bypass.