
kartlanpwn
Technical analysis and proof-of-concept for CVE-2024-45200, a stack-based buffer overflow in Mario Kart 8 Deluxe's Pia P2P networking library,…

Technical analysis and proof-of-concept for CVE-2024-45200, a stack-based buffer overflow in Mario Kart 8 Deluxe's Pia P2P networking library,…

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

Windows LPE exploit for CVE-2021-40449, a use-after-free in win32kfull!GreResetDCInternal, leveraging token leaking, kernel gadget abuse, and…

CVE-2017-8890 exploit implementation with detailed analysis documents for privilege escalation on Ubuntu 16.04 and Nexus 6P kernels.

Demonstrates a proof-of-concept exploit for CVE-2021-43297, a deserialization vulnerability in Apache Dubbo's Hessian2 protocol, with provider and…

A lightweight test harness designed to speed up shellcode development by providing an execution environment with integrated crash diagnostics and…

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

Proof-of-concept local privilege escalation exploit for a Linux qdisc rate-table race condition, using BPF heap grooming and a pipe leak to gain root.

Proof-of-concept exploit for CVE-2023-4911 (Looney Tunables), targeting a buffer overflow in glibc's GLIBC_TUNABLES parsing. Includes vulnerability…

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

Binaries, drivers, PoCs and other stuff on Hydroph0bia vulnerability (CVE-2025-4275)

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Generic heap overflow exploit for CVE-2022-24834 in Redis Lua cjson library, with auto gadget finder, symbol resolution, and reverse shell handler…

This repository contains the sources and documentation for the LVI-LFB Control Flow Hijacking attack PoC (CVE-2020-0551)

Proof-of-concept exploit for CVE-2015-2546, with accompanying research paper and blog detailing the vulnerability analysis and exploitation technique.

Reports and POCs for CVE 2024-43570 and CVE-2024-43535

Personal collection of exploits including n-days, 0-days, CTFs, kernel and browser vulnerabilities for security research and penetration testing.

[CVE-2017-10235] Description and PoC of VirtualBox E1000 device Buffer Overflow