
CVE-2021-44168
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3.

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3.

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

PoC code for the LPE and RCE (CVE-2024-31903) attacks against the IBM Sterling B2B Integrator

Remote code execution in Microvirt MEmu

Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode…

OS Command Injection Vulnerability via Cache Clearing Scheduler in Reolink Desktop Application

Remote code execution exploit for CVE-2022-26809 targeting Windows RPC heap buffer overflow with msfvenom shellcode integration and meterpreter…

Proof-of-concept exploit for CVE-2025-0117 in GlobalProtect, achieving privilege escalation to SYSTEM via a backdoored installer and DLL injection.

PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause…

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

My experiments in weaponizing Nim (https://nim-lang.org/)

Search for Unix binaries that can be exploited to bypass system security restrictions.

BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

PoC CVE-2025-49144

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux