Ross ROSS = Recommend OSS · open-source software intelligence for agents

zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 observed · 2026-08-28

github.com/zhzyker/exphub · Python observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2345
  • days_rel: n/a
  • days_push: 1977
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

4291 stars · 1081 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, Struts2, Tomcat, Fast, Nexus, Solr, JBoss, and Drupal. Each script verifies (poc) or exploits (exp/rce/shell/webshell) a specific vulnerability.

Use cases

  • verify whether a server is vulnerable to a specific CVE
  • exploit a Weblogic deserialization RCE to get a reverse shell
  • upload a webshell to a vulnerable Tomcat instance
  • test Fast versions for deserialization vulnerabilities
  • run a quick poc check during a penetration test

When to choose

  • you need a ready-made, tested exploit script for a specific CVE in Weblogic, Struts2, Tomcat, Fast, or similar middleware
  • you want lightweight single-purpose scripts rather than a full scanning framework
  • you are doing authorized penetration testing or CTF challenges against these products

When to avoid

  • you need an actively maintained tool with new CVE coverage (development stopped in 2021; the author moved to vulmap)
  • you want a unified scanner rather than one script per vulnerability
  • you require a project with a clear license for commercial or compliance-sensitive use

Facets

library · maturity abandoned

penetration-testing security vulnerability-scanning security penetration-testing developer-tools python cli exploit-scripts poc cve rce webshell getshell red-team vulnerability-exploitation linux

1 source

Member repositories

RepositoryRoleHealth v2
zhzyker/exphubmain32

For agents

markdown · JSON · MCP: product_card(name="zhzyker/exphub")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem