Rce Open Source Projects
Browse 195 Rce open source projects, ranked by GitHub stars. Find the most popular Rce tools and libraries.
nomi-sec/PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
Metrics details
| Stars | 7,920 |
Mr-xn/Penetration_Testing_POC
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
Metrics details
| Stars | 7,427 |
reddelexc/hackerone-reports
Top disclosed reports from HackerOne
Metrics details
| Stars | 6,366 |
LandGrey/SpringBootVulExploit
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
Metrics details
| Stars | 6,144 |
zhuifengshaonianhanlu/pikachu
一个好玩的Web安全-漏洞测试平台
Metrics details
| Stars | 4,450 |
mbechler/marshalsec
Metrics details
| Stars | 3,696 |
swisskyrepo/SSRFmap
Automatic SSRF fuzzer and exploitation tool
Metrics details
| Stars | 3,593 |
zhzyker/vulmap
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能
Metrics details
| Stars | 3,525 |
tarunkant/Gopherus
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
Metrics details
| Stars | 3,399 |
threedr3am/learnjavabug
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
Metrics details
| Stars | 2,689 |
JoyChou93/java-sec-code
Java web common vulnerabilities and security code which is base on springboot and spring security
Metrics details
| Stars | 2,670 |
r0eXpeR/redteam_vul
红队作战中比较常遇到的一些重点系统漏洞整理。
Metrics details
| Stars | 2,523 |
joaomatosf/jexboss
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
Metrics details
| Stars | 2,521 |
tr0uble-mAker/POC-bomber
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
Metrics details
| Stars | 2,368 |
david942j/one_gadget
The best tool for finding one gadget RCE in libc.so.6
Metrics details
| Stars | 2,338 |
tom0li/collection-document
Collection of quality safety articles. Awesome articles.
Metrics details
| Stars | 2,109 |
gquere/pwn_jenkins
Notes about attacking Jenkins servers
Metrics details
| Stars | 2,097 |
insightglacier/Dictionary-Of-Pentesting
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
Metrics details
| Stars | 2,065 |
JKornev/hidden
🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc
Metrics details
| Stars | 2,045 |
p0dalirius/Awesome-RCE-techniques
Awesome list of step by step techniques to achieve Remote Code Execution on various apps!
Metrics details
| Stars | 1,943 |
brightio/penelope
Penelope Shell Handler
Metrics details
| Stars | 1,922 |
1N3/BlackWidow
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
Metrics details
| Stars | 1,812 |
tanjiti/sec_profile
爬取secwiki和xuanwu.github.io/sec.today,分析安全信息站点、安全趋势、提取安全工作者账号(twitter,weixin,github等)
Metrics details
| Stars | 1,582 |
vladko312/SSTImap
Automatic SSTI detection tool with interactive interface
Metrics details
| Stars | 1,578 |
XiphosResearch/exploits
Miscellaneous exploit code
Metrics details
| Stars | 1,576 |
v3n0m-Scanner/V3n0M-Scanner
Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns
Metrics details
| Stars | 1,570 |
gobysec/Goby
Attack surface mapping
Metrics details
| Stars | 1,513 |
nemesida-waf/waf-bypass
Check your WAF before an attacker does
Metrics details
| Stars | 1,503 |
1ndianl33t/Gf-Patterns
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
Metrics details
| Stars | 1,443 |
chompie1337/SMBGhost_RCE_PoC
Metrics details
| Stars | 1,395 |
jdonsec/AllThingsSSRF
This is a collection of writeups, cheatsheets, videos, books related to SSRF in one single location
Metrics details
| Stars | 1,381 |
adon90/pentest_compilation
Compilation of commands, tips and scripts that helped me throughout Vulnhub, Hackthebox, OSCP and real scenarios
Metrics details
| Stars | 1,365 |
nccgroup/singularity
A DNS rebinding attack framework.
Metrics details
| Stars | 1,306 |
SkyBlueEternal/thinkphp-RCE-POC-Collection
thinkphp v5.x 远程代码执行漏洞-POC集合
Metrics details
| Stars | 1,193 |
n0b0dyCN/redis-rogue-server
Redis(<=5.0.5) RCE
Metrics details
| Stars | 1,166 |
oskarsve/ms-teams-rce
Metrics details
| Stars | 1,104 |
veracode-research/rogue-jndi
A malicious LDAP server for JNDI injection attacks
Metrics details
| Stars | 1,086 |
feihong-cs/Java-Rce-Echo
Java RCE 回显测试代码
Metrics details
| Stars | 1,012 |
Ridter/redis-rce
Redis 4.x/5.x RCE
Metrics details
| Stars | 980 |
cn-panda/JavaCodeAudit
Getting started with java code auditing 代码审计入门的小项目
Metrics details
| Stars | 930 |
RhinoSecurityLabs/CVEs
Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs
Metrics details
| Stars | 903 |
klezVirus/CVE-2021-40444
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
Metrics details
| Stars | 832 |
0ang3el/aem-hacker
Metrics details
| Stars | 815 |
leohearts/awd-watchbird
A powerful PHP WAF for AWD
Metrics details
| Stars | 789 |
mcw0/PoC
Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.
Metrics details
| Stars | 783 |
LandGrey/spring-boot-upload-file-lead-to-rce-tricks
spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧
Metrics details
| Stars | 760 |
smgorelik/Windows-RCE-exploits
The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are uploaded for education purposes for red and blue teams.
Metrics details
| Stars | 748 |
GhostTroops/TOP
TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things
Metrics details
| Stars | 733 |
1120362990/vulnerability-list
在渗透测试中快速检测常见中间件、组件的高危漏洞。
Metrics details
| Stars | 725 |
bhdresh/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
Metrics details
| Stars | 724 |
timip/OSWE
OSWE Preparation
Metrics details
| Stars | 684 |
doyensec/awesome-electronjs-hacking
A curated list of awesome resources about Electron.js (in)security
Metrics details
| Stars | 675 |
lintstar/About-Attack
一个旨在通过应用场景 / 标签对 Github 红队向工具 / 资源进行分类收集,降低红队技术门槛的手册【持续更新】
Metrics details
| Stars | 638 |
jm33-m0/mec
for mass exploiting
Metrics details
| Stars | 615 |
orangetw/awesome-jenkins-rce-2019
There is no pre-auth RCE in Jenkins since May 2017, but this is the one!
Metrics details
| Stars | 610 |
nccgroup/freddy
Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans
Metrics details
| Stars | 583 |
Dliv3/redis-rogue-server
Redis 4.x/5.x RCE
Metrics details
| Stars | 577 |
ZecOps/CVE-2020-0796-RCE-POC
CVE-2020-0796 Remote Code Execution POC
Metrics details
| Stars | 573 |
jamf/CVE-2020-0796-RCE-POC
CVE-2020-0796 Remote Code Execution POC
Metrics details
| Stars | 573 |
Li4n0/revsuit
RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.
Metrics details
| Stars | 564 |
