



MAL-009: Insecure Chaining of Flags T and TT in Zip for Linux

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…


[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

Proof of concept exploit of Windows Update Orchestrator Service Elevation of Privilege Vulnerability

Exploit used against the Netgear R6700v3 during Pwn2Own Austin 2021

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

EaseUS MobiMover 6.0.5 Build 21620 - Insecure Files and Folders Permissions

InjectProc - Process Injection Techniques [This project is not maintained anymore]

PoC of CVE-2022-20474

my extended take on Mark Brand's CVE 2016-3861 libutils bug