This project is a repository of漏洞库 (vulnerability library) identified by wy876. The goal is to maintain and share a collection of documented security vulnerabilities. The primary focus is on exposing and documenting vulnerabilities, particularly SQL injection and remote code execution flaws, found in web applications and system components. The repository contains exploit code and detailed explanations for each vulnerability. It is intended as a resource for security researchers, penetration testers, and developers to understand and address potential security weaknesses.
The repository provides a comprehensive collection of vulnerabilities, predominantly SQL injection and remote code execution, across various systems and plugins. It contains detailed descriptions, CVEs and exploit details, helping in practical analysis and remediation. The resource's breadth across a range of technologies (WordPress, systems, etc.) makes it useful for broad penetration testing validation. Each entry offers clear, actionable information for reproducing and evaluating the vulnerabilities.
- SQL Injection Vulnerabilities: A significant portion of the identified vulnerabilities involve SQL injection flaws across a variety of applications and systems (e.g., databases, web applications).
- Remote Code Execution Vulnerabilities: Several vulnerabilities allow for remote code execution, enabling attackers to execute arbitrary commands on vulnerable systems.
- File Upload Vulnerabilities: Various entry points allow for insecure file uploads, leading to potential remote code execution or file system compromise.
- Authentication Bypass / Credential Theft: Several vulnerabilities allow attackers to bypass authentication mechanisms, or compromise user credentials.
- Information Disclosure: Various vulnerabilities lead to information leakage, exposing sensitive data like API keys, database credentials, or confidential logs.
The repository is actively maintained with new vulnerabilities added frequently, primarily in March and December 2025 indicating recent and ongoing updates. The consistent addition of new CVE findings suggests it's a valuable, though evolving, resource for security professionals. Despite the continuous additions, the quality and thoroughness of each entry vary.
This repository is beneficial for security professionals, researchers, and developers involved in penetration testing, vulnerability assessments, or secure development practices. It helps in understanding common vulnerability patterns and provides a valuable resource for security research and education. It can be used for training, testing security tools, and monitoring potential security risks in various software systems.
