
CVE-2021-4034
Exploit for CVE-2021-4034 (pkexec) targeting CentOS 8, allowing custom command execution via modified pwnkit-dry-run.c. Includes compilation and…

Exploit for CVE-2021-4034 (pkexec) targeting CentOS 8, allowing custom command execution via modified pwnkit-dry-run.c. Includes compilation and…

Windows x86 PoC: Stack‑based buffer overflow with custom shellcode on legacy 32-bit Windows.

Proof-of-concept exploit for CVE-2014-7911 targeting Android 4.4.4 on Nexus5, using a custom ROP chain to escalate privileges and write files as the…

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Demonstrates CVE-2022-34302, a Secure Boot bypass via the New Horizon Datasys signed bootloader whose built-in custom PE/COFF loader executes…

CVE-2026-11105 PoC demonstrating a stack buffer overflow in a custom Base64 decoder; crafted oversized input overwrites stack memory and enables…

PowerShell script for local privilege escalation on Windows via the PrintNightmare vulnerability (CVE-2021-1675), adding a local admin user or…

CTF pwn challenge writeup exploiting CVE-2021-4034 (pkexec) via heap manipulation, with Ghidra-based reverse engineering and a custom shelly.so…

Custom C exploit for CVE-2020-8423 targeting MIPS routers, featuring hooked open() syscall and tailored for Linux kernel 2.6.31.

Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure…

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

This is a custom ASCII AND/SUB Encoder developed during my preparation for the legacy OSCE/CTP course

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap

Return-Oriented Programming (ROP) chain exploit PoC for binary exploitation, demonstrating gadget selection and chain execution.