
CVE-2025-43529
Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Automated Application Generation for Stack Overflow Types on Wireless Routers

Real world and CTFs exploiting web/binary POCs.

SonicWall SMA-100 Unauth RCE Exploit (CVE-2021-20038)

Spectre exploit

Infoleak and PC control poc for CVE-2015-6620 (24445127), I'll add after conference

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

exploit for CVE-2026-42945

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Reproducer for Linux kernel memory corruption vulnerability CVE-2020-14386, deployed as a Kubernetes pod to test node vulnerability by triggering a…

CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback

Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

CVE-2019-0708 - BlueKeep (RDP)

CVE-2018-4248: Out-of-bounds read in libxpc during string serialization.