Back to rankings

p0dalirius/Awesome-RCE-techniques

Dockerfilepodalirius.net

Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

rceframeworkawesome-listcodeexecutionexploitbugbountycms
Star Growth
Stars
1.9k
Forks
217
Weekly Growth
Issues
12
5001k1.5k
May 2022Sep 2023Feb 2025Jul 2026
README

Awesome RCE techniques

Awesome list of techniques to achieve Remote Code Execution (RCE) on various apps!
Number of RCE techniques YouTube Channel Subscribers

Goal of this project

The goal of this project is to provide an OpenSource knowledge database of all the techniques to achieve Remote Code Execution (RCE) on various applications. All of these techniques also comes with a test environnement (usually a Docker image) for you to train these techniques.

Techniques

Work in progress

These techniques are a work in progress. You can help us finish them by opening a pull request!

Troubleshooting

Report all the issues on https://github.com/p0dalirius/Awesome-RCE-techniques/issues.

Contributors

Pull requests are welcome. Feel free to open an issue if you want to add other Remote Code Execution (RCE) techniques.

Related repositories
Mr-xn/Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

HTMLApache License 2.0penetration-testingpoc
mrxn.net
7.4k2k
reddelexc/hackerone-reports

Top disclosed reports from HackerOne

PythonPyPIwriteupshackerone
6.4k1.1k
k8gege/K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

PowerShellMIT Licenseexploit0day
k8gege.org
6.2k2.1k
LandGrey/SpringBootVulExploit

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

JavaMavenspringbootspringboot-actuator-rce
6.1k1.3k
zhzyker/vulmap

Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

PythonPyPIGNU General Public License v3.0exploitcve
github.com/zhzyker/vulmap
3.5k572
tarunkant/Gopherus

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

PythonPyPIMIT Licensercessrf
3.4k403
JoyChou93/java-sec-code

Java web common vulnerabilities and security code which is base on springboot and spring security

JavaMavenjavacode
2.7k769
tr0uble-mAker/POC-bomber

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

PythonPyPIGNU General Public License v3.0pocvulnerability-scanner
2.4k387
gquere/pwn_jenkins

Notes about attacking Jenkins servers

PythonPyPIjenkinspentest
2.1k326
insightglacier/Dictionary-Of-Pentesting

Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。

Shellpentestingfuzzing
2.1k373
JKornev/hidden

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Cwindowssecurity
2k503
brightio/penelope

Penelope Shell Handler

PythonPyPIGNU General Public License v3.0ptytty
1.9k219