



Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Technical analysis and professional exploit for CVE-2025-60751, a stack-based buffer overflow in GeographicLib. Includes a pwntools-based Ret2Libc…

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

CVE Realtek SD card reader. CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40432, CVE-2024-40431

CVE-2026-53359 - Draft

Proof-of-concept exploit for CVE-2018-10933, demonstrating SSH authentication bypass via MSG_USERAUTH_SUCCESS injection. Includes Docker setup and…

CVE-2020-8597 pppd buffer overflow poc

CVE-2026-5172: buffer overflow in extract_addresses() on crafted resource record PoC

Proof of Concept for CVE-2014-3466 (GnuTLS buffer overflow: session id length check)

PoC for CVE-2020-0601 - CryptoAPI exploit

PoC exploit server for CVE-2015-7547

potential memory corruption vulnerabilities in IPv6 networks.