
cve-2019-13132-lab
CVE-2019-13132 — libzmq CURVE INITIATE stack overflow → RCE. Working exploit + Docker lab.

CVE-2019-13132 — libzmq CURVE INITIATE stack overflow → RCE. Working exploit + Docker lab.

Docker-based lab to reproduce CVE-2023-4863 (heap buffer overflow in libwebp) with automated crash demonstration, patched vs vulnerable comparison,…

Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.

CTF challenge and exploit script for CVE-2018-10933, a libSSH authentication bypass, with Docker setup and walkthrough.

Docker-based lab and proof-of-concept exploit for CVE-2025-32463, a sudo chroot local privilege escalation, featuring a vulnerable Ubuntu container…

Fully dockerized Linux kernel debugging environment

Go package that aids in binary analysis and exploitation

Self-contained demo for GitLab RCE exploiting two Ruby memory corruption bugs in the Oj parser through notebook diff rendering.

Technical writeup of CVE-2025-24104: an iOS sandbox escape via symlink validation bypass in backup restoration, enabling arbitrary file reads outside…

An exploit primitive in linux kernel inspired by DirtyPipe

This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.

Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo

Generic heap overflow exploit for CVE-2022-24834 in Redis Lua cjson library, with auto gadget finder, symbol resolution, and reverse shell handler…

Proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code…

An offensive security researcher + an AI vs. a fresh n-day: building the first public PoC for CVE-2026-53435 in one Friday night. Raw 8h20m log…

CVE-2026-17544 — PHP bcmath bccomp() OOB write (stack smashing). Verified: crash on 8.4.23/8.5.8, fixed in 8.4.24. GHSA-x692-q9x7-8c3f

Demo-ing CVE-2017-1000253 in a container

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code execution via…