awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

161 个仓库

Awesome GitHub RepositoriesWeb Application Exploits

Proof of concept exploits targeting vulnerabilities in web applications and plugins.

Explore 161 awesome GitHub repositories matching part of an awesome list · Web Application Exploits. Refine with filters or upvote what's useful.

Awesome Web Application Exploits GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • alibaba/sentinelalibaba 的头像

    alibaba/Sentinel

    23,126在 GitHub 上查看↗

    Sentinel is a microservice flow control framework designed for managing traffic limits, distributed circuit breaking, and adaptive overload protection. It serves as a traffic shaping component that defines resource boundaries to regulate request flow and ensure reliability across distributed systems. The project provides a real-time monitoring dashboard for tracking resource metrics and performance bottlenecks across service clusters. It includes a visual interface for the real-time management of flow control and circuit breaking rules, allowing parameters to be updated without restarting the

    Security research and testing tools for microservices.

    Java
    在 GitHub 上查看↗23,126
  • k8gege/k8toolsk8gege 的头像

    k8gege/K8tools

    6,167在 GitHub 上查看↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    Identifies and exploits vulnerabilities in web applications, including SQL injection and deploying web shells.

    PowerShell0daybrute-forcebypass
    在 GitHub 上查看↗6,167
  • christophetd/log4shell-vulnerable-appchristophetd 的头像

    christophetd/log4shell-vulnerable-app

    1,142在 GitHub 上查看↗

    Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

    Vulnerable application for testing Log4j exploits.

    Javalog4shell
    在 GitHub 上查看↗1,142
  • mochazz/thinkphp-vulnMochazz 的头像

    Mochazz/ThinkPHP-Vuln

    1,125在 GitHub 上查看↗

    关于ThinkPHP框架的历史漏洞分析集合

    Collection of exploits for ThinkPHP framework vulnerabilities.

    在 GitHub 上查看↗1,125
  • ridter/redis-rceRidter 的头像

    Ridter/redis-rce

    978在 GitHub 上查看↗

    Redis 4.x/5.x RCE

    Exploit for remote code execution via Redis misconfiguration.

    Python
    在 GitHub 上查看↗978
  • rhinosecuritylabs/cvesRhinoSecurityLabs 的头像

    RhinoSecurityLabs/CVEs

    897在 GitHub 上查看↗

    Collection of security research and exploits.

    Python
    在 GitHub 上查看↗897
  • ambionics/laravel-exploitsambionics 的头像

    ambionics/laravel-exploits

    290在 GitHub 上查看↗

    Exploit for CVE-2021-3129

    Collection of exploits for Laravel framework vulnerabilities.

    Python
    在 GitHub 上查看↗290
  • duc-nt/cve-2020-6287-exploitduc-nt 的头像

    duc-nt/CVE-2020-6287-exploit

    96在 GitHub 上查看↗

    PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR module: https://github.com/rapid7/metasploit-framework/pull/13852/commits/d1e2c75b3eafa7f62a6aba9fbe6220c8da97baa8 This PoC only create user with unauthentication permission and no more administrator permission set. This project is created only for educational purposes and cannot be used for law violation or personal gain. The author of this project is not responsible for any possible harm caused by the materials of this project. Original

    Exploit for SAP remote code execution.

    Python
    在 GitHub 上查看↗96
  • willygailo/cve-2026-3891-linuxwillygailo 的头像

    willygailo/CVE-2026-3891-Linux

    1在 GitHub 上查看↗

    ⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions ≤ 1.5.0).

    Arbitrary file upload exploit for WordPress plugin.

    Python
    在 GitHub 上查看↗1
  • hieuminhnv/cve-2022-21587-pocH

    hieuminhnv/CVE-2022-21587-POC

    0在 GitHub 上查看↗

    Expl

    在 GitHub 上查看↗0
  • chaosec2021/spring-cloud-function-spel-rceC

    chaosec2021/Spring-cloud-function-SpEL-RCE

    0在 GitHub 上查看↗

    Exploit for Spring Cloud Function SpEL injection.

    在 GitHub 上查看↗0
  • redteampentesting/cve-2020-13935R

    RedTeamPentesting/CVE-2020-13935

    0在 GitHub 上查看↗

    Exploit for Apache Solr remote code execution.

    在 GitHub 上查看↗0
  • sh286/cve-2020-8163S

    sh286/CVE-2020-8163

    0在 GitHub 上查看↗

    Exploit for specific framework vulnerabilities.

    在 GitHub 上查看↗0
  • 0nise/vuldebug0

    0nise/vuldebug

    0在 GitHub 上查看↗

    Tools for debugging and exploiting web vulnerabilities.

    在 GitHub 上查看↗0
  • axyanzzzz/tongwebejbexploitA

    Axyanzzzz/TongWebEJBExploit

    0在 GitHub 上查看↗

    Exploit for EJB-based remote code execution in application servers.

    在 GitHub 上查看↗0
  • itsthalisman/cve-2026-3359-expI

    itsthalisman/cve-2026-3359-exp

    0在 GitHub 上查看↗

    SQL injection exploit for WordPress plugin.

    在 GitHub 上查看↗0
  • horizon3ai/cve-2022-39952H

    horizon3ai/CVE-2022-39952

    0在 GitHub 上查看↗

    Exploit for Fortinet firewall remote code execution.

    在 GitHub 上查看↗0
  • deepingh0st/cve-2022-28346D

    DeEpinGh0st/CVE-2022-28346

    0在 GitHub 上查看↗

    Exploit for specific application vulnerabilities.

    在 GitHub 上查看↗0
  • ydking0911/cve-2026-4060-pocY

    ydking0911/CVE-2026-4060-PoC

    0在 GitHub 上查看↗

    Time-based SQL injection exploit for WordPress plugin.

    在 GitHub 上查看↗0
  • ollypwn/cve-2020-0601O

    ollypwn/CVE-2020-0601

    0在 GitHub 上查看↗

    Exploit research for cryptographic validation vulnerabilities.

    在 GitHub 上查看↗0
上一个123456…9下一个
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Web Application Exploits