
CVE-2021-3156
Proof-of-concept exploit for CVE-2021-3156, a heap-based buffer overflow in sudo that allows local privilege escalation to root on Ubuntu 20.04 and…

Proof-of-concept exploit for CVE-2021-3156, a heap-based buffer overflow in sudo that allows local privilege escalation to root on Ubuntu 20.04 and…

The exploit targets a critical privilege escalation vulnerability in macOS versions Monterey, Ventura, and Sonoma.

Batch script exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows. Targets git, GitHub CLI, VS Code, and other Git…

Proof-of-concept exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo enabling local privilege escalation to root.…

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code…

CVE-2018-4185: iOS 11.2-11.2.6 kernel pointer disclosure introduced by Apple's Meltdown mitigation.

Local privilege escalation exploit for CVE-2025-62676.

Free and Open Source Reverse Engineering Platform powered by rizin

PoCs and exploits for CVEs discovered by NebuSec.

incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi

Automates setup of binary exploitation challenges by patching ELF binaries, fetching matching linkers, unstripping libc, and generating pwntools…

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

A Proof-of-Concept bootkit and UEFI boot application inspired by Petya ransomware, written in Assembly, C, and C++

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…