
imMapper
Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.

Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

Proof-of-concept exploit for CVE-2023-0386, a Linux OverlayFS local privilege escalation vulnerability. Demonstrates how incorrect file capability…

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

POC shows how to leak postgresql stuff cause hugefile sub-system. Based on https://x.com/spendergrsec/status/1993794163880718700?s=20

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241

Technical analysis of CVE-2021-3493, an Ubuntu OverlayFS local privilege escalation vulnerability, including root cause explanation and affected…

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

Exploit for CVE-2024-5274, a Chrome V8 DCHECK bytecode mismatch vulnerability that provides out-of-bounds read/write primitives for browser…

A curated list of awesome OSCP resources