
vucsa
Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

CVE-2016-5195 (Dirty COW) exploit that modifies /etc/passwd to escalate privileges and spawn a root shell on vulnerable Linux kernels.

CVE-2020-15368, aka "How to exploit a vulnerable driver"

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

eBPF-based Linux kernel local privilege escalation exploit targeting CVE-2021-3490. Provides root shell access on vulnerable Ubuntu kernels 5.8.0-25…

Proof-of-concept exploit for CVE-2023-36874, a Windows elevation of privilege vulnerability. Demonstrates exploitation on vulnerable Windows clients…

This repo contains PoCs for vulnerable Windows drivers.

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…

Proof-of-concept exploit for CVE-2025-6019, a local privilege escalation in libblockdev/udisks. Creates an XFS image with SUID bash to gain root…

Environment with vulnerable kernel for exploitation of the TEE driver (CVE-2021-44733)

Windows kernel driver exploits for HackSys Extreme Vulnerable Driver, demonstrating binary exploitation and privilege escalation for security…

all 4.4 ubuntu aws instances are vulnerable

Full exploit for D-Link DCS-5020L, POC crash for others that are vulnerable as well.

CVE-2013-6282 kernel exploit that overwrites ptmx.fsync handler and uevent_helper string for local privilege escalation on vulnerable Linux systems.