
bl_sbx
itunesstored & bookassetd sbx escape

itunesstored & bookassetd sbx escape

Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.

Collection of CVE(work) on tenserflow binary pwning it

Demo project how to bypass the disable_functions security control of PHP on Linux

Educational analysis and proof-of-concept code for CVE-2021-4034 (pkexec local privilege escalation), with detailed comments explaining the…

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

A curated list of awesome OSCP resources

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

Summary of Cyber Security interview questions I have been through, hope this helps

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

POC shows how to leak postgresql stuff cause hugefile sub-system. Based on https://x.com/spendergrsec/status/1993794163880718700?s=20

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

Implementation of Max Kellermann's exploit for CVE-2022-0847

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).