
cve-2013-2094
original cve-2013-2094 exploit and a rewritten version for educational purposes

original cve-2013-2094 exploit and a rewritten version for educational purposes

Walkthrough of CVE-2020-15416 buffer overflow exploit for Netgear R7000 router, including QEMU user-mode debugging environment setup and detailed…

There are 2 exploitation methods that exploit CVE-2022-27666. For more info on how to use these code bases please check my blog.

Exploit for CVE-2024-5274, a Chrome V8 DCHECK bytecode mismatch vulnerability that provides out-of-bounds read/write primitives for browser…

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

Example payload for CVE-2022-21894

Technical write-up and exploit code for CVE-2019-11932, a double-free vulnerability in WhatsApp for Android that leads to remote code execution via a…

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

Demo project how to bypass the disable_functions security control of PHP on Linux

CVE-2020-15368, aka "How to exploit a vulnerable driver"

An demonstration of how to exploit double-fetch vulnerability CVE-2016-6516

POC shows how to leak postgresql stuff cause hugefile sub-system. Based on https://x.com/spendergrsec/status/1993794163880718700?s=20

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.

Implementation of Max Kellermann's exploit for CVE-2022-0847

My n-day exploit for CVE-2019-18634 (local privilege escalation)

Collection of CVE(work) on tenserflow binary pwning it

OpenBSD remote overflow