
cve-2026-43499-m3q-azf1
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

PoC for CVE-2026-67822 stack overflow in Tenda W6-S /goform/wifiSSIDset: DoS reproducer, QEMU MIPS shim, and conceptual RCE payload skeleton.

Academic Research Edition - T1: User-mode evasion (obfuscation + syscall gateway), T2: BYOVD kernel bridge, T3: DMA hardware (future work).


An exploit to CVE-2020-0423, which is a Binder deffered work UAF.

CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

MOC3ingbird Exploit for Live2D (CVE-2023-27566)

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Local privilege escalation exploit for ASUS AsIO3.sys driver (CVE-2025-3464). Chains a TOCTOU authentication bypass with a kernel decrement primitive…

Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption

Researching CVE published originally by longterm.io

CVE-2024-35250 PoC - Optimized & Condensed Form of Varwara's PoC

Productization efforts of CVE-2020-11179 Adreno-Qualcomm-GPU bug, original poc by Ben Hawkes of P0

poc for CVE-2022-32981 under work

Proof-of-concept exploit for CVE-2024-32002, demonstrating RCE via git clone with malicious submodules and symlinks on case-insensitive filesystems.

fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

exploits for CVE-2024-20017