
vmprotect-research
Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

Proof-of-concept exploit for CVE-2024-21338, a kernel vulnerability. Demonstrates exploitation technique for security research and vulnerability…

C++ exploit for CVE-2021-1732 targeting Windows privilege escalation on Win10 1803-20H2 and Server 2019/2004. Provides kernel-level elevation of…

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

Trigger and exploit code for CVE-2014-4113

PoC for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons…

Generic heap overflow exploit for CVE-2022-24834 in Redis Lua cjson library, with auto gadget finder, symbol resolution, and reverse shell handler…

Local privilege escalation proof-of-concept for CVE-2026-64531 abusing OVS kernel datapath to corrupt credentials and gain root via sudoers injection.

Proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code…

Proof-of-concept exploit for OpenSSL CVE-2020-1967, a denial-of-service vulnerability in TLS 1.3 signature_algorithms_cert handling, with…

Chrome V8 RCE exploit for CVE-2021-30632 targeting Windows systems. Tested on Chrome 91-93. Includes JS POC and in-the-wild bug analysis reference.

Proof-of-concept exploit for CVE-2021-33739 and CVE-2021-26868, demonstrating local privilege escalation on Windows systems through binary…

Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader…

Proof-of-concept exploit for CVE-2017-1000117, a critical remote code execution vulnerability in Git. Includes Go and shell-based PoCs for testing…

Proof-of-concept exploit for OpenSSL buffer overflow vulnerabilities CVE-2022-3602 and CVE-2022-3786, demonstrating remote code execution via crafted…

Exploit for CVE-2026-2005, a heap overflow in PostgreSQL's pgcrypto extension leading to remote code execution. Includes PoC generators, Docker lab,…

Shell script exploit for CVE-2023-2640 and CVE-2023-32629 targeting OverlayFS vulnerability on Ubuntu 20.04 to achieve local privilege escalation to…

One-liner exploit for CVE-2022-0847 (Dirty Pipe) Linux kernel vulnerability enabling arbitrary file overwrite and privilege escalation via a single…