
CVE-2020-27955-LFS
Windows RCE exploit for CVE-2020-27955 targeting git-lfs, affecting GitHub Desktop, VS Code, and other Git clients via crafted .bat/powershell…

Windows RCE exploit for CVE-2020-27955 targeting git-lfs, affecting GitHub Desktop, VS Code, and other Git clients via crafted .bat/powershell…

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

PowerShell script for local privilege escalation on Windows via the PrintNightmare vulnerability (CVE-2021-1675), adding a local admin user or…

Python exploit for CVE-2025-11001 targeting 7-Zip on Windows, leveraging symlink creation to achieve code execution when 7-Zip runs with Admin…

Python exploit for CVE-2025-11001 targeting 7-Zip symlink vulnerability on Windows. Requires admin privileges; creates malicious archives to trigger…

must run this native binary with system privilege

Exploit for CVE-2022-20186 in Arm Mali kernel driver, achieving arbitrary kernel code execution from untrusted app domain to disable SELinux and gain…

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

Demonstrates a critical WebAssembly OOB read/write via table index confusion, leaking host memory and potentially enabling code execution in WASM…

Demonstrates a local code execution exploit for Foxit PDF Reader via XFA-based PDFs, with step-by-step attack reproduction and extension to related…

Proof-of-concept exploit for D-Link DIR-825M stack buffer overflow and command injection in /boafrm/formDiskFormat, enabling remote code execution as…

Technical analysis and proof-of-concept for CVE-2024-6387, a race condition in OpenSSH signal handling enabling unauthenticated remote code execution…

Zero-click remote code execution exploit for CVE-2021-0326 targeting Android devices, including the Peloton Bike, with a proof-of-concept requiring…

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3.

Local privilege escalation exploit for macOS 10.14.2 and earlier, leveraging CVE-2019-6225. Includes kernel exploit code with SMAP limitations and…