
gsscred-move-uaf
CVE-2018-4343: Proof-of-concept for a use-after-free in the GSSCred daemon on macOS and iOS.

CVE-2018-4343: Proof-of-concept for a use-after-free in the GSSCred daemon on macOS and iOS.

Android LPE exploit for CVE-2026-43499 targeting OPPO PMG110 (kernel 6.6). Uses futex PI UAF to gain root and install a su daemon via LD_PRELOAD.

POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon

CVE-2018-4280: Mach port replacement vulnerability in launchd on macOS 10.13.5 leading to local privilege escalation and SIP bypass.

Python exploit for CVE-2022-42475 heap overflow in Fortinet SSLVPN daemon. Delivers reverse shell via pwntools with customizable target, port, and…

Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

exploits for CVE-2024-20017

Classic stack-based buffer overflow in War FTP Daemon 1.65 demonstrating old-school remote code execution through malformed FTP commands.

translating original python exploit to C

Local privilege escalation exploit targeting PackageKit's TOCTOU race condition (CVE-2026-41651). Escalates from unprivileged user to root via polkit…

FortiOS buffer overflow vulnerability