
CVE-2026-1457
Provides a detailed analysis and proof-of-concept for CVE-2026-1457, an authenticated buffer overflow in TP-Link VIGI C385 web API leading to remote…

Provides a detailed analysis and proof-of-concept for CVE-2026-1457, an authenticated buffer overflow in TP-Link VIGI C385 web API leading to remote…

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

ARM buffer overflow challenge exploiting NFC tag input on Raspberry Pi. Includes hardware assembly guide, server code, and flag retrieval for CTF and…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Curated collection of CTF challenge solutions covering binary exploitation, reverse engineering, and system security with detailed write-ups.

CTF challenge deploying CVE-2022-0847 (Dirty Pipe) exploit to overwrite read-only files. Includes setup scripts, hints, and verification for kernel…

Proof-of-concept exploit for CVE-2019-12937: a stack buffer overflow in ToaruOS gsudo allowing local privilege escalation to root through crafted…

Detailed technical analysis and proof-of-concept for CVE-2019-12735, an arbitrary code execution vulnerability in Vim/Neovim via modeline sandbox…

Python-based remote buffer overflow exploit targeting CVE-2003-0172. Accepts host and port arguments to deliver a payload for penetration testing and…

CTF challenge and exploit script for CVE-2018-10933, a libSSH authentication bypass, with Docker setup and walkthrough.

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

CVE-2019-19470 exploit replication with source code, WinDbg commands, PEB modification, and decompilation examples for educational red team training.

Proof-of-concept exploit for CVE-2024-6387, a remote code execution vulnerability. Provides a targeted exploitation tool for security testing and…

Collection of detailed and optimized(?) write-ups for various CTF challenges

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Build a database of libc offsets to simplify exploitation

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Files + Writeups for DownUnderCTF 2022 Challenges