
CVE-2021-31166
Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

NGINX RCE exploits

Reproducible AI-assisted vulnerability rediscovery of CVE-2026-42945 in nginx, including technical analysis, PoC trigger, and patch validation for…

Collections of Orange Tsai's public presentation slides.

Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.

Cisco RV110w UPnP stack overflow

CVE-2026-42945 Nginx Rift

Analyzes CVE-2026-42945, an NGINX rewrite heap overrun, providing a differential detector, deterministic DoS PoC, and a credited RCE port with…

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

Proof-of-concept exploit for CVE-2023-25234, a stack overflow vulnerability in Tenda AC6 routers, enabling remote code execution via crafted HTTP…

Iot Camera 0day

Proof-of-concept exploit for CVE-2022-30114, a heap-based buffer overflow in Fastweb FastGate routers. Sends a crafted HTTP Authorization header to…

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

Demonstrates CVE-2026-9256 heap buffer overflow in nginx's ngx_http_rewrite_module with PoC scripts for heap/libc leaks and worker crash.

A proof of concept of an SEH overflow with arbitrary dll injection

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

Stack-based buffer overflow in MiniShare 1.4.1 reachable through a single HTTP PUT request.