allen-110/exploitarium — explained in plain English
Analysis updated 2026-05-18
Study documented proof-of-concept writeups for real software vulnerabilities
Look up whether a specific tool or library has a known documented issue in this archive
Reference a specific vulnerability writeup for security research or education
| allen-110/exploitarium | 8bit64k/cronalytics | alibaba-damo-academy/rynnworld-4d | |
|---|---|---|---|
| Stars | 69 | 69 | 69 |
| Language | Python | Python | Python |
| Setup difficulty | moderate | easy | — |
| Complexity | 4/5 | 2/5 | — |
| Audience | researcher | ops devops | researcher |
Figures from each repo's GitHub metadata at analysis time.
Each folder is a separate proof-of-concept with its own context, there is no single unified setup for the whole archive.
Exploitarium is a personal archive of security research maintained by one researcher. It brings together proof-of-concept writeups and vulnerability findings that the author previously kept in separate standalone repositories, consolidating them into a single collection with one folder per finding. Each folder documents a specific software vulnerability the author discovered or investigated, covering a wide range of well known tools and libraries such as 7-Zip, AnyDesk, Docker, Firefox, FFmpeg, Ghidra, ImageMagick, Gitea, libssh2, Nmap, VLC, and several others. The README lists over twenty of these folders along with how many tracked files each one contains, and notes whether the entry came from merging an older standalone repository or was added directly to this archive. The repository includes a section describing how the author verified the consolidation was done correctly. When the old standalone repositories were folded into this one, the author compared the file contents of each former repo against the matching folder here, checking that file paths, file types, permission bits, and the underlying file content all matched exactly. According to the README, this check covered 12 former repositories and 96 tracked files with no mismatches found. The purpose of this repository, based on the README, is to serve as a reference archive for security researchers who want to study documented proof-of-concept exploits and vulnerability writeups. The author mentions being open to specific software requests to look at, and provides a Discord contact for anyone who wants to discuss or collaborate on this research. Since it is a collection of individual proof-of-concept folders rather than a single installable tool, there is no unified setup process described. Each folder likely needs to be reviewed on its own to understand the specific vulnerability, the affected software version, and how the proof of concept works.
A consolidated archive of one researcher's public proof-of-concept writeups covering vulnerabilities in tools like Docker, Firefox, Ghidra, and libssh2.
Mainly Python. The stack also includes Python.
Setup difficulty is rated moderate, with roughly 30min to a first successful run.
Mainly researcher.
This repo across BitVibe Labs
double-check against the repo, no cap.