
CVE-2024-23222-Coruna-Exploit-Kit-Deobfuscated
Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

Android 14 kernel exploit for Pixel7/8 Pro

Detailed technical write-up and proof-of-concept exploit for CVE-2023-33733, a remote code execution vulnerability in the Reportlab Python library…

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

Proof-of-concept exploit for Jenkins Templating Engine plugin sandbox bypass (CVE-2025-31722) enabling remote code execution via malicious Groovy…

Hands-on lab demonstrating Apache Struts2 OGNL injection (CVE-2017-5638) with step-by-step system analysis, exploitation, sandbox bypass, and…

CVE-2026-22692 - Critical Twig Sandbox Bypass via collect()->mapInto() allowing RCE/LFI/XXE in October CMS

Proof-of-concept exploit for CVE-2025-55182, a critical RCE vulnerability in Next.js Server Actions. Exploits insecure deserialization in the React…

PoC exploit for an authenticated RCE in CrafterCMS via Groovy sandbox bypass (CVE-2025-6384)

Educational PoC for CVE-2017-8291 (GhostButt) demonstrating remote command execution via Python PIL/Pillow EPS image processing with GhostScript…

PoC for CVE-2017-8386 Git-Shell sandbox bypass vulnerability.

Detailed technical analysis and proof-of-concept for CVE-2019-12735, an arbitrary code execution vulnerability in Vim/Neovim via modeline sandbox…

Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

Math.js Expression Parser RCE

POC for CVE-2026-21858

Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline:…

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Proof-of-concept exploit for CVE-2025-49131, a sandbox escape in FastGPT allowing arbitrary file read/write, import bypass, and remote code execution…