bikini/exploitarium
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
About the project
An archive of public proof-of-concept exploits and vulnerability research writeups covering browsers, archivers, SSH, Docker and other widely used software. Collected by a researcher to teach and attract people into security.
Useful for
- Study the PoC structure for a vulnerability in a specific product
- Reproduce an exploit in an isolated lab environment
- Use the writeups as learning material on fuzzing methodology
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 5 stars today.
- Top new repositories in the last 4 months: #93.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 5,105
- Stars in a day
- 5
- Forks
- 1,308
- Issues and pull requests
- 15
- Watchers
- 114
- Language
- Python
- Created
- June 23, 2026
- Last push
- July 15, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 13, 2026Top new repositories in the last 4 months: #93
Similar projects
-
7.0
SnailSploit/Claude-Red
A curated library of drop-in SKILL.md files for the Claude Skills system that primes Claude with offensive security methodology, from SQL injection to EDR evasion and exploit development.
-
6.2
vxcontrol/pentagi
Autonomous multi-agent system in Go for automated penetration testing: AI agents plan and execute steps in an isolated Docker sandbox with 20+ tools (nmap, metasploit, sqlmap).
-
5.0
hezhanleiok/freesub
Automatically tests and publishes subscription pools of free proxy nodes (VLESS, VMess, Trojan, Shadowsocks, Hysteria2, TUIC, AnyTLS), filtering out dead and hijacked nodes via real HTTPS handshakes and TLS validation.
-
4.9
tsymbaluyk/maskgate
PII masking service that detects passports, tax IDs, SNILS, bank cards, phones, medical data and secrets in text and files and masks them before they reach ChatGPT, Claude, Gemini. Source code is proprietary; this repo…
-
4.3
zhihui-hu/one-ip
Web tool for IP lookups: identifies datacenter, VPN, Tor and proxy usage, rates reputation from 0 to 100, shows ASN, WHOIS, DNS, CDN, geolocation and checks AI service reachability.
-
4.2
realchendahuang/feedsieve
A Chrome extension that flags spam accounts on X (Twitter) with a yellow border and lets you block them manually or in bulk via the native API, synced across all devices.