Open Source Security Arsenal
Curated intelligence repository of battle-tested open-source security tools, exploits, and pentesting frameworks.
Security Tools
Nextjs_RCE_Exploit_Tool Exploit for CVE-2025-55182 & CVE-2025-66478
[EXPLOIT] Vailyn - PoC Exploit
UnknownVailyn A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python
[EXPLOIT] NextRce - PoC Exploit
UnknownNextRce React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)
one_gadget The best tool for finding one gadget RCE in libc.so.6
[EXPLOIT] Gopherus - PoC Exploit
UnknownGopherus This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
pocsuite3 pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.
Xiaomi-HyperOS-BootLoader-Bypass A PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings.
device-activity-tracker A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive device-activity patterns. (WhatsApp / Signal)
Awesome-POC 一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
ysoserial A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
[EXPLOIT] xray - PoC Exploit
Unknownxray 一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
[EXPLOIT] vulmap - PoC Exploit
Unknownvulmap Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能