GitHub repo leaderboard by stars, growth rate and activity.
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
Automatic SSTI detection tool with interactive interface
DianXing - AI-Driven End-to-End Code Security Auditing
n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)
AiGPT started from the concept of CVE‑2024‑27956 , the WP Automatic CSV injection — but has been completely rebuilt into a multi‑vector, unauthenticated WordPress exploitation engine. It now chains 13 real‑world CVEs to create an administrator account or drop a web shell directly, then automatically injects a reverse shell into the active theme
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms | HTML | 7,491 | last pushed 14 hours ago | |
| 2 | Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。 | Shell | 2,073 | last pushed 3 years ago | |
| 3 | A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website. | Python | 1,822 | last pushed 5 months ago | |
| 4 | Automatic SSTI detection tool with interactive interface | Python | 1,638 | last pushed 2 weeks ago | |
| 5 | DianXing - AI-Driven End-to-End Code Security Auditing | — | 873 | last pushed 3 months ago | |
| 6 | n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0) | Python | 260 | last pushed 6 months ago | |
| 7 | AiGPT started from the concept of CVE‑2024‑27956 , the WP Automatic CSV injection — but has been completely rebuilt into a multi‑vector, unauthenticated WordPress exploitation engine. It now chains 13 real‑world CVEs to create an administrator account or drop a web shell directly, then automatically injects a reverse shell into the active theme | Python | 133 | last pushed 3 months ago |
All · 11,658