
CVE-2020-13768
Stack-based buffer overflow in MiniShare 1.4.1 reachable through a single HTTP PUT request.

Stack-based buffer overflow in MiniShare 1.4.1 reachable through a single HTTP PUT request.

Proof-of-concept exploit for CVE-2023-26976, a stack overflow vulnerability in Tenda AC6 routers, enabling remote code execution via crafted HTTP…

Exploit for CVE-2014-6271 (Shellshock) enabling remote code execution via crafted HTTP headers against vulnerable Bash versions.

Proof-of-concept exploit for CVE-2022-30114, a heap-based buffer overflow in Fastweb FastGate routers. Sends a crafted HTTP Authorization header to…

Proof-of-concept exploit for CVE-2023-25234, a stack overflow vulnerability in Tenda AC6 routers, enabling remote code execution via crafted HTTP…

NGINX RCE exploits

Collections of Orange Tsai's public presentation slides.

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Cisco RV110w UPnP stack overflow


Proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code…

CVE-2013-2028 python exploit

RTSPServer Code Execution Vulnerability CVE-2018-4013

NGINX `ngx_http_dav_module` Heap Buffer Overflow via `size_t` Underflow (Remote DoS / Potential RCE)

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

Docker-based lab and Python exploit for CVE-2013-2028, an Nginx 1.3.9 chunked-parser integer overflow, covering canary recovery, mprotect, and…

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code execution via…

Analyzes CVE-2026-42945, an NGINX rewrite heap overrun, providing a differential detector, deterministic DoS PoC, and a credited RCE port with…