SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Exploit Projects
-
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
gef
GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
-
DefaultCreds-cheat-sheet
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
-
PhoneSploit-Pro
An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.
-
-
-
Ghost
Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device. (by EntySec)
-
-
-
-
-
-
ambiguous-png-packer
Craft PNG files that appear completely different in Apple software [NOW PATCHED]
-
-
-
puncia
Panthera(P.)uncia - Official CLI utility for Osprey Vision, Subdomain Center & Exploit Observer.
-
-
Telegram-Trilateration
Proof of concept for abusing Telegram's "People Near Me" feature and tracking people's location
-
RomBuster
RomBuster is a router exploitation tool that allows to disclosure network router admin password.
-
-
Firmware_Slap
Discovering vulnerabilities in firmware through concolic analysis and function clustering.
-
stm32f1-picopwner
Dump read-out protected STM32F1's with a Pi Pico - A Pi Pico implementation of @JohannesObermaier's, Marc Schink's and Kosma Moczek's Glitch and FPB attack to bypass RDP (read-out protection) level 1 on STM32F1 chips
First I'd like to point out that "Decryptor" is an ill-chosen term: there's no encryption mechanism here, RDP is a software lock based on an internal flash state.
This dongle is very likely to be this original attack https://github.com/JohannesObermaier/f103-analysis/tree/mast... but now packaged. If you want to read more this repo has the best doc: https://github.com/CTXz/stm32f1-picopwner. It's a multi-step attack where a payload is executed from persisted SRAM (RDP1 means you can read/write to it) after a quick reset. The fact that they mention freezing the chip heavily weighs in that direction since it's needed for higher clock chips.
-
pentest-ai
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
Project mention: Show HN: Ptai – an MCP that chains low-sev findings into RCE | news.ycombinator.com | 2026-05-19
Python Exploit discussion
Python Exploit related posts
-
CR4SH3R — Tool for Detecting Vulnerabilities in WordPress Plugins
-
Bit Vectors and my first steps into assembly
-
Journey to understand format string attack (Part 1)
-
GEF – GDB Enhanced Features
-
Get Exploits of CVE,GHSA,EDB,ZDI,PSS,WLB,H1,Talos and Huntr IDs with One Utility
-
Beej's Quick Guide to GDB (2009)
-
Puncia – Subdomain and Exploit Hunter Powered by AI
-
A note from our sponsor - SaaSHub
www.saashub.com | 11 Jun 2026
Index
What are some of the best open-source Exploit projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | pwntools | 13,528 |
| 2 | gef | 8,206 |
| 3 | DefaultCreds-cheat-sheet | 6,589 |
| 4 | PhoneSploit-Pro | 5,893 |
| 5 | AutoSploit | 5,240 |
| 6 | wesng | 4,860 |
| 7 | Ghost | 3,346 |
| 8 | APT_REPORT | 3,004 |
| 9 | CTF | 2,503 |
| 10 | pwn_jenkins | 2,092 |
| 11 | PocOrExp_in_Github | 1,165 |
| 12 | featherduster | 1,130 |
| 13 | ambiguous-png-packer | 1,062 |
| 14 | CVE-2023-38831-winrar-exploit | 788 |
| 15 | like-dbg | 771 |
| 16 | puncia | 662 |
| 17 | SIET | 594 |
| 18 | Telegram-Trilateration | 590 |
| 19 | RomBuster | 543 |
| 20 | cve-maker | 487 |
| 21 | Firmware_Slap | 479 |
| 22 | stm32f1-picopwner | 292 |
| 23 | pentest-ai | 266 |