

Proof-of-concept exploit for CVE-2025-11579, a denial-of-service vulnerability in rardecode that triggers an out-of-memory crash via a crafted RAR…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Automatic analysis of SWF files based on some heuristics. Extensible via plugins.

Proof-of-concept for CVE-2023-33802, a denial-of-service vulnerability in SumatraPDF 3.4.6 32-bit, triggered by opening two large text files, causing…

Another RTTI Parsing IDA plugin

Proof-of-concept for CVE-2025-62454 that triggers a Windows kernel crash (BSOD) in cldflt.sys via a crafted FSCTL request, causing a page fault in…

Kernel Stack info leak at exportObjectToClient function

Frida-based proof-of-concept demonstrating authentication bypass in Telegram Android by hooking SharedConfig.checkPasscode to always return true,…

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in…

asadbg is a framework of tools to aid in automating live debugging of Cisco ASA devices

Reproducible CVE-2026-36834 proof-of-concept demonstrating an out-of-bounds array read in LibRaw's Panasonic RW2 decoder, with mutation script and…

Proof-of-concept exploit for CVE-2025-50420 demonstrating infinite recursion in Poppler's pdfseparate via crafted /Annots dictionaries, causing…

Proof-of-concept for CVE-2025-27363 demonstrating a heap buffer overflow in FreeType 2.13.0 via a crafted variable font, with ASAN-verified crash…

PoC and analysis of a zero-click DoS in Android's DNG SDK, with crafted DNG samples, an NDK crash harness, and UBSan/IntSan reproduction of the…

SolarWinds Serv-U CVE-2026-28318: unauthenticated Content-Encoding: deflate crash. Root-cause analysis (invalid free of an interior pointer -> heap…

Minimal CVE-2025-69421 reproducer demonstrating a NULL pointer dereference in OpenSSL PKCS#12 processing via a malformed PFX file with absent…

Proof-of-concept for CVE-2022-31902, a denial-of-service vulnerability in Notepad++ (x86) triggered by the Find All feature on crafted text files,…