
CVE-2024-36587
Proof-of-concept exploit for CVE-2024-36587 demonstrating local privilege escalation in dnscrypt-proxy via binary planting, with Docker-based…

Proof-of-concept exploit for CVE-2024-36587 demonstrating local privilege escalation in dnscrypt-proxy via binary planting, with Docker-based…

CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers…

Reflective PE packer.

exploit for CVE-2026-42945

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

CVE-2026-32746 - GNU InetUtils telnetd LINEMODE SLC Buffer Overflow PoC (pre-auth RCE, CVSS 9.8)

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer


CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

CVE-2013-2028 python exploit

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Honor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading


wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.