
CVE-2020-1493
Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

Proof-of-concept exploit for OpenSSL CVE-2020-1967, a denial-of-service vulnerability in TLS 1.3 signature_algorithms_cert handling, with…

Chrome V8 RCE exploit for CVE-2021-30632 targeting Windows systems. Tested on Chrome 91-93. Includes JS POC and in-the-wild bug analysis reference.

Deep-dive analysis and exploitation walkthrough of CVE-2016-4622, a WebKit JavaScriptCore memory disclosure vulnerability via Array.slice TOCTOU race…

SnatchBox (CVE-2020-27935) is a sandbox escape vulnerability and exploit affecting macOS up to version 10.15.x

Technical analysis and proof-of-concept exploit for CVE-2023-20938, a use-after-free vulnerability in the Android kernel's Binder driver, enabling…

A plugin that provides resources for beginners to learn reverse engineering using Binary Ninja. It automatically installs several other plugins, and…

Proof-of-concept exploit for CVE-2025-6554, demonstrating V8 sandbox escape via addressof and fakeobj primitives to achieve arbitrary read/write.…

Exploit analysis for CVE-2014-4378: information disclosure in Apple CoreGraphics via crafted PDF, enabling memory layout leak and bypass of ASLR,…

Proof-of-concept exploit for CVE-2021-33739 and CVE-2021-26868, demonstrating local privilege escalation on Windows systems through binary…

Analysis and proof-of-concept exploit code for CVE-2020-1054, a Windows kernel privilege escalation vulnerability, with technical write-up linked.

PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430,…

Exploit for CVE-2021-4034 (pkexec) targeting CentOS 8, allowing custom command execution via modified pwnkit-dry-run.c. Includes compilation and…

Exploit PoC for CVE-2022-29968 by Joseph Ravichandran and Michael Wang

POC for RCE vulnerability in ParseExcel library, and ParseXLSX too, as a depending library

UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

Proof-of-concept exploit for CVE-2024-6768, a Windows CLFS.sys driver vulnerability causing BSoD via crafted .BLF file. Includes source code and…