
MSRMapper
Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified…

Technical analysis of CVE-2026-52924, a critical use-after-free in Linux kernel SCTP stale cookie handling, including root cause, attack flow, fix,…

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Proof-of-concept exploit for CVE-2026-21055 demonstrating arbitrary command execution via improperly exported Android components in Samsung Bixby.…

CVE-2026-12485

Curated vulnerability research repository with in-depth writeups, proof-of-concept scripts, and IOC listings for real-world CVEs. Covers root cause…

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…

Reproduction and analysis toolkit for CVE-2025-55423, providing exploit verification and vulnerability assessment capabilities for security…

Proof-of-concept exploit for CVE-2026-3888, written in C. Demonstrates vulnerability exploitation and binary-level attack techniques for security…

Educational PoC for CVE-2026-8838, a critical RCE vulnerability in Amazon Redshift Python Driver via unsafe eval() in vector_in(). Includes technical…

Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository…

Proof-of-concept exploit for CVE-2019-7711, a format string vulnerability in Green Hills INTEGRITY RTOS. Demonstrates a full attack chain with memory…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

C exploit for CVE-2025-38248 supporting ROP and data-only attack techniques for binary exploitation research and vulnerability verification.

Proof-of-concept for CVE-2026-21508, demonstrating a DLL hijacking attack on Windows 11 that escalates privileges by loading a crafted DLL into…

Proof-of-concept exploit code for critical sudo vulnerabilities CVE-2025-32462 and CVE-2025-32463, demonstrating privilege escalation attack vectors.

Exploit for CVE-2025-27591, a local privilege escalation in the Below service, leveraging a world-writable directory and symlink attack to modify…