
CVE-2019-13764
Full exploit for CVE-2019-13764 targeting V8 JavaScript engine on Linux, with root cause analysis and proof-of-concept code from Haboob Research Team.

Full exploit for CVE-2019-13764 targeting V8 JavaScript engine on Linux, with root cause analysis and proof-of-concept code from Haboob Research Team.

Linux kernel exploit implementations targeting CVE-2005-0736 and CVE-2005-1263, providing proof-of-concept code for privilege escalation on…

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

Batch script exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows. Targets git, GitHub CLI, VS Code, and other Git…

Exploit for CVE-2022-46395, an Arm Mali kernel driver vulnerability, achieving arbitrary kernel code execution to disable SELinux and gain root on…

Exploit for CVE-2022-20186 in the Arm Mali kernel driver, achieving arbitrary kernel code execution to disable SELinux and gain root on Google Pixel…

Linux kernel use-after-free (UAF) privilege escalation exploit for CVE-2018-17182, providing root shell access on affected kernels (3.16 to 4.18.8).…

Linux kernel privilege escalation exploits targeting CVE-2006-2451 and CVE-2006-3626, providing proof-of-concept code for local privilege escalation…

ARM buffer overflow challenge exploiting NFC tag input on Raspberry Pi. Includes hardware assembly guide, server code, and flag retrieval for CTF and…

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

POE code for CVE-2017-1000112 adapted to both funtion on a specific VM and Escape a Docker

Curated repository of exploits, proof-of-concept code, and vulnerability research presentations from the phoenhex team, focused on binary…

Proof-of-concept for CVE-2025-65741 demonstrating dylib injection in Sublime Text 3 on macOS via unsigned code, with a compiled .dylib payload and…

Research repository with source code and documentation for CVE-2021-3493 (privilege escalation) and CVE-2022-3357 (RCE), demonstrating combined…

RCE exploit for CVE-2020-27955 targeting Git LFS on Windows, with .bat and PowerShell payloads for testing Git, GitHub CLI, VS Code, and other tools.

Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520

Demonstrates CVE-2021-21300 arbitrary code execution via malicious Git hooks on case-insensitive filesystems, including exploit steps and defensive…

Batch and PowerShell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability affecting Git, GitHub Desktop, VS Code, and other…