
Notepad-8.9.6-PoC
Proof-of-concept scripts for three vulnerabilities in Notepad++ <= 8.9.6, patched in v8.9.6.1 (2026-05-26) CVE-2026-48770 / CVE-2026-48778 /…

Proof-of-concept scripts for three vulnerabilities in Notepad++ <= 8.9.6, patched in v8.9.6.1 (2026-05-26) CVE-2026-48770 / CVE-2026-48778 /…

Techniques and tools for Windows kernel exploitation, covering pool overflow exploitation, segment heap metadata abuse, and debugging scripts for…

Automates setup of binary exploitation challenges by patching ELF binaries, fetching matching linkers, unstripping libc, and generating pwntools…

Python-based buffer overflow exploit targeting SLmail (CVE-2003-0264) for educational penetration testing and vulnerability demonstration.

A curated list of awesome OSCP resources

Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via…

binary patching from Python

Collection of DEF CON 30 CTF challenge binaries, build scripts, and solve scripts for practicing binary exploitation and reverse engineering.

Linux kernel exploit development notes and scripts for CTF challenges, covering initramfs extraction, msg_msg/ldt_struct abuse, and practical…

Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts

Demonstrates CVE-2026-9256 heap buffer overflow in nginx's ngx_http_rewrite_module with PoC scripts for heap/libc leaks and worker crash.

Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage…

Single-stage exploit chain for CVE-2020-6418 (Chrome RCE) chained with Windows privilege escalation to SYSTEM, with build scripts and prebuilt…

Proof-of-concept exploit and technical analysis for a WinRAR path traversal vulnerability enabling code execution via crafted archives with binary…

Proof-of-concept exploit for CVE-2026-8461, a heap out-of-bounds write in FFmpeg's MagicYUV decoder, achieving remote code execution via…