Exploitarium
A free, organized archive of real, already-disclosed security vulnerabilities and how they were exploited — a reference library for people who need to understand attacks in order to defend against them.
🔗 Visit ExploitariumDescription
Security professionals learn to defend systems partly by studying how systems actually get broken, but that research is normally scattered across blog posts, conference talks and disclosure databases with no consistent format. Exploitarium collects that knowledge in one place: over 47 proof-of-concept folders covering disclosed vulnerabilities in real, well-known software, each with a technical writeup explaining what the flaw was and how it was exploited.
Exploitarium is a curated, open-source GitHub archive covering vulnerabilities across web applications (Discourse, Nextcloud, Gitea), system software (Firefox, OpenSSH, Docker, QEMU), libraries (FFmpeg, ImageMagick, libssh2) and communication platforms (Discord), written in a mix of C, Python and shell scripts. It's built around a responsible-disclosure and good-faith-research framing, with the maintainer citing a background in fuzzing methodology and published security research, and it carries an explicit anti-malicious-use disclaimer. With over 4,600 GitHub stars, 1,300 forks and 113 watchers, it's an actively followed reference rather than an obscure repository, and it functions as a study resource similar in spirit to Exploit-DB or PoC-in-GitHub, but organized as a browsable, contribution-friendly project rather than a raw database dump.
💬 Our review
The short version: if you're a security researcher, pentester or bug-bounty hunter who wants to study real, disclosed exploitation techniques in one organized place, Exploitarium is a free, actively-maintained reference with real community traction behind it.
Against Exploit-DB, the long-standing default in this space, Exploitarium's edge is organization and readability — proof-of-concept folders with accompanying writeups rather than a flat searchable dump — plus it's structured as an open GitHub project that accepts contributions rather than a static submission pipeline. It's not a tool you install or a service you subscribe to; it's a knowledge resource, so the comparison to buy-vs-alternatives doesn't really apply the way it would for software — the real question is whether you trust the curation and the responsible-disclosure framing, and 4,600+ stars plus a stated fuzzing-research background suggest a credible maintainer rather than someone repackaging others' work without context. Best suited for people doing legitimate security research or learning defensive techniques from real-world cases; anyone browsing this without a security background should treat it as educational reading, not a how-to guide.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Gratuit, dépôt GitHub ouvert
Pros
47+ dossiers de PoC organisés avec writeups techniques, pas un simple dump
Couvre des logiciels réels et connus (Firefox, OpenSSH, Docker, Discourse, Nextcloud...)
Cadre de divulgation responsable explicite avec disclaimer anti-usage malveillant
Traction communautaire réelle : 4 600+ étoiles, 1 300+ forks, 113 watchers
Cons
Contenu sensible par nature — nécessite un usage encadré et responsable
Pas un outil logiciel à proprement parler, plutôt une ressource documentaire
Qualité et profondeur des writeups probablement variable selon les contributeurs
