
CVE-2022-22077
BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

Historical archive of exploit code and tools from TESO, including remote exploits, DDoS agents, and development utilities for educational security…

CVE-2026-19193 Proof of Concept

Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing

CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

Exploiting Parsec for Windows to gain SYSTEM privileges

Reliable remote code execution exploit for CVE-2026-25243 targeting jemalloc Redis. Executes arbitrary commands via a single crafted RESTORE command…

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

IKEv2, ikeext.dll, CVE-2026-33824, double free, heap grooming, ROP, SKF fragmentation, Windows exploit, anti-debug, obfuscation, API hooking,…

Exploit for CVE-2026-31431 targeting aarch64 systems. Provides proof-of-concept code for vulnerability verification and security testing.

Evince/xreader/Atril RCE exploit to CVE-2026-46529

Detailed proof-of-concept and technical analysis for CVE-2026-2441, a Chrome CSS use-after-free vulnerability enabling sandboxed renderer RCE via…

exploit for CVE-2026-42945