
wasm2c-tableflip
wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64

Local privilege escalation exploit targeting a Linux kernel io_uring AF_VSOCK reference-count bug, using page-cache manipulation to overwrite…

Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

Kernel exploit for CVE-2026-43499 on Samsung Galaxy A17 achieving root via KDP bypass, KASLR recovery, and forged workqueue execution with persistent…

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

Generates WebP images that trigger CVE-2023-4863 heap buffer overflow in libwebp, using tunable OFFSET/VALUE constants for exploit testing and…

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

PowerShell proof-of-concept that triggers CVE-2026-62737, an arbitrary kernel call in ExecutionContext.sys, causing a controlled kernel crash on…

Deep-dive analysis of Windows CLFS type confusion (CVE-2022-24481) with root-cause explanation, exploitation flow, kernel gadget details, and working…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))

Proof-of-concept exploit for CVE-2026-64600 in RefluXFS, demonstrating the flaw and providing technical context for detection, patching, and further…

Linux kernel local privilege escalation exploit with automated prerequisite audit for CVE-2026-46300, validating patch status, XFRM ESP-in-TCP…