
CVE-2024-48208
This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

Demonstrates CVE-2026-9256 heap buffer overflow in nginx's ngx_http_rewrite_module with PoC scripts for heap/libc leaks and worker crash.

A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua scripting enabling remote code execution. Targets specific Redis…

Educational PoC and analysis of CVE-2021-4034 (PwnKit) local privilege escalation vulnerability in polkit's pkexec, with a Docker-based lab for…

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Reproduction of CVE-2019-18634, a sudo privilege escalation exploit via buffer overflow in pwfeedback. Includes Docker-based environment for…

Exploit scripts for CVE-2025-62507, a stack buffer overflow in Redis 8.2.0. Provides x86-64 and ARM64 ROP chain exploits with shellcode generation…

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via…

Proof-of-concept exploit for CVE-2022-31630, an out-of-bounds read vulnerability in PHP's GD extension. Demonstrates crash and memory disclosure in…

Dive into CFF font and coincidently learn about a bof in cff parsing from some jailbreak. just for fun

CVE-2021-25741 POC in Zig

Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure…

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo's chroot feature via malicious NSS library loading. Includes…

CVE-2019-5736 implemented in a self-written container runtime to understand the exploit.

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation vulnerability in sudo allowing chroot jail escape via specific sudoers…

Proof-of-concept exploit for CVE-2024-55656, an integer overflow in RedisBloom leading to heap-based OOB read/write and remote code execution in…