
CVE-2020-0022
Research repository documenting BlueFrag (CVE-2020-0022) Android Bluetooth heap overflow experiments, including GDB crash analysis and memcpy…

Research repository documenting BlueFrag (CVE-2020-0022) Android Bluetooth heap overflow experiments, including GDB crash analysis and memcpy…

Proof-of-concept exploit for CVE-2026-85046 in Chrome 152.0.7977.75, demonstrating type confusion in sort() to achieve arbitrary code execution via a…

Root-cause analysis and working exploit for CVE-2026-78938, a V8 TurboFan type confusion leading to arbitrary read/write within the compressed heap.…

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

Local privilege escalation exploit for Windows HTTP.sys integer overflow (CVE-2026-62735), demonstrating crash and full SYSTEM shell via nonpaged…

Proof-of-concept exploit for D-Link DIR-825M stack buffer overflow and command injection in /boafrm/formDiskFormat, enabling remote code execution as…

Proof-of-concept for CVE-2026-62735, an integer overflow in http.sys leading to heap overflow and SYSTEM shell. Includes crash log and stack trace…

Proof-of-concept exploit for CVE-2026-9973, a V8 Turboshaft load elimination bug leading to memory corruption, with ongoing sandbox escape research.

A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™…

Exploit for CVE-2026-31431: a 732-byte Python script that exploits a straight-line logic flaw to gain root on all Linux distributions since 2017.

C PoC for CVE-2026-31431, an unprivileged Linux LPE exploiting AF_ALG page cache corruption to overwrite /usr/bin/su and gain root.

C exploit for CVE-2026-31431, a Linux kernel page-cache corruption vulnerability in the AF_ALG AEAD path, using splice() to influence cached file…

Zig implementation of the Copy Fail Linux LPE (CVE-2026-31431) providing a standalone binary to exploit the vulnerability for security research and…

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66…

Proof-of-concept exploit for CVE-2021-4034 (PwnKit) that escalates privileges to root on vulnerable Linux systems.

LPE exploit for CVE-2026-31431 CopyFail. Compatible with Python 3.9.

Exploit for CVE-2021-3156 (Sudo Baron Samedit) targeting Linux x64 with multiple variants for different glibc and sudo versions.

Exploit for CVE-2021-4034, a memory corruption vulnerability in pkexec of polkit, enabling local privilege escalation to root on Linux systems.