
Januscape
KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

CVE-2026-46316 guest-to-host KVM/arm64 escape exploit exploiting a race condition in vGIC-ITS emulation to achieve host kernel code execution from an…

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Arbitrary file read exploit for the Windows UPnP Device Host service.

Demonstrates a critical WebAssembly OOB read/write via table index confusion, leaking host memory and potentially enabling code execution in WASM…

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

Container-based lab with proof-of-concept exploits for two critical sudo vulnerabilities: host validation bypass (CVE-2025-32462) and NSS library…

Demonstration of CVE-2021-3656, a KVM nested virtualization vulnerability allowing L2 guest to bypass VMLOAD/VMSAVE intercepts and read/write host…

Destructive Docker container escape exploit for CVE-2019-5736, overwriting host /usr/bin/docker-runc with a payload triggered via docker exec.

Ruby-based proof-of-concept exploit for McAfee Host Intrusion Prevention (HIP) CVE-2016-8007, demonstrating privilege escalation via a local…

Proof-of-concept exploit for Oracle VirtualBox VGA out-of-bounds read vulnerability, demonstrating address leaking from VirtualBox components on…

Proof-of-concept exploit for CVE-2019-5736, appending a payload to the host runc binary via Docker container escape.

Python-based remote buffer overflow exploit targeting CVE-2003-0172. Accepts host and port arguments to deliver a payload for penetration testing and…

Proof-of-concept exploit for CVE-2019-5736, a Docker container escape via runc binary overwrite, enabling host shell access through libseccomp…

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

VirtualBox E1000 Guest-to-Host Escape


PoC for triggering buffer overflow via CVE-2020-0796