
CVE-2024-29943
A Pwn2Own 2024 SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE

A Pwn2Own 2024 SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE

Activation cache poisoning to elevate from medium to high integrity (CVE-2024-6769)

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

Binary Exploitation and Reverse-Engineering (from assembly into C)

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224

Local privilege escalation exploit for macOS XNU kernel (CVE-2026-43724) that uses an out-of-bounds write in dyld shared-cache slide walk to gain a…

UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

Local privilege escalation PoC for a Linux kernel SCTP ASCONF DEL-IP use-after-free, demonstrating a root shell from an unprivileged local user on…

Pardus Software Local Privilege Escalation PoC - affected from <= 1.0.4

Step-by-step walkthrough for exploiting CVE-2015-1328 (OverlayFS) to escalate privileges from a low-privileged user to root on Ubuntu 14.04. Includes…