
CVE-2024-28397-Exploit-Automation
A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

A collection of samples and material related to process injection

Linux kernel privilege-escalation exploit for CVE-2026-46242, a race-condition use-after-free in epoll, with 99% reliable root on desktops, servers,…

A happy heap editor to support your exploitation process :slightly_smiling_face:

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow

Chrome Renderer 1day RCE via Type Confusion in Async Stack Trace (v8ctf submission)

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new…

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration,…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and…

[Linux] Two Privilege Escalation techniques abusing sudo token

Linux kernel TLS subsystem exploit for CVE-2024-58239, achieving privilege escalation via a double-free vulnerability in tcp_rcv_state_process.…

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution via prototype chain vulnerability in React Server Components.…