
CVE-2023-38041-POC
Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

Educational RCE exploit for CVE-2021-44228 (Log4Shell) with RMI server and client demonstrating vulnerability recurrence via calculator popup.

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Proof-of-concept exploit for CVE-2013-2977: IBM Lotus Notes PNG integer overflow leading to arbitrary code execution when a malicious email is opened…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

A demo server for CVE-2016-3955 (UBOAT)

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

Proof-of-concept for CVE-2026-33317, an out-of-bounds write in OP-TEE PKCS#11 TA, demonstrating Secure World heap corruption via a malformed…

Proof-of-concept exploit for CVE-2015-7547, a glibc getaddrinfo() stack-based buffer overflow. Includes server and client components to trigger the…

Bypass for Symantec Endpoint Protection's Client User Interface Password

Proof-of-concept exploit for CVE-2018-10933, demonstrating SSH authentication bypass via MSG_USERAUTH_SUCCESS injection. Includes Docker setup and…

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

Proof-of-concept exploit for CVE-2024-2432 demonstrating local privilege escalation on Windows via arbitrary file delete through symbolic link attack…

Exploit POC Code for CVE-2024-55968

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

Safenet Authentication Client Privilege Escalation - CVE-2021-42056