zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2345
- days_rel: n/a
- days_push: 1977
- n_releases_24m: 0
Adoption not part of the score
4291 stars · 1081 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, Struts2, Tomcat, Fast, Nexus, Solr, JBoss, and Drupal. Each script verifies (poc) or exploits (exp/rce/shell/webshell) a specific vulnerability.
Use cases
- verify whether a server is vulnerable to a specific CVE
- exploit a Weblogic deserialization RCE to get a reverse shell
- upload a webshell to a vulnerable Tomcat instance
- test Fast versions for deserialization vulnerabilities
- run a quick poc check during a penetration test
When to choose
- you need a ready-made, tested exploit script for a specific CVE in Weblogic, Struts2, Tomcat, Fast, or similar middleware
- you want lightweight single-purpose scripts rather than a full scanning framework
- you are doing authorized penetration testing or CTF challenges against these products
When to avoid
- you need an actively maintained tool with new CVE coverage (development stopped in 2021; the author moved to vulmap)
- you want a unified scanner rather than one script per vulnerability
- you require a project with a clear license for commercial or compliance-sensitive use
Facets
library · maturity abandoned
penetration-testing security vulnerability-scanning security penetration-testing developer-tools python cli exploit-scripts poc cve rce webshell getshell red-team vulnerability-exploitation linux
1 source
- readme: https://github.com/zhzyker/exphub · fetched 2026-08-28 · 22ebb650b17c
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| zhzyker/exphub | main | 32 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem