
CVE-2021-4034
Root exploit for CVE-2021-4034 (PwnKit) that abuses pkexec's out-of-bounds write to escalate privileges to root on Linux systems.

Root exploit for CVE-2021-4034 (PwnKit) that abuses pkexec's out-of-bounds write to escalate privileges to root on Linux systems.

Practical lab focused on vulnerability analysis and exploit development, using FreeFloat FTP Server 1.0 as an educational buffer overflow case study…

Educational lab demonstrating EternalBlue (MS17-010) exploitation against Windows 7 using Metasploit, including post-exploitation, WannaCry…

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

Proof-of-concept exploit for CVE-2021-4034, a Polkit privilege escalation vulnerability, demonstrating local privilege escalation on vulnerable…

A personal tool in GO for my usual first enumeration steps on a target

Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)

CVE-2026-31431 (Copy Fail) novel exploit: live code corruption via page cache. Overwrites libc exit() code through MAP_PRIVATE page sharing — affects…

Metasploit RCE on HFS 2.3 - CVE-2014-62

CVE-2025-24071

CVE-2013-1775 Exploit written in Perl

Proof-of-concept exploit for Linux kernel CVE-2026-31431 (Copy Fail) that abuses AF_ALG to corrupt setuid-root binaries in page cache, achieving…

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

Generates malicious RAR archives exploiting a path traversal vulnerability in unRAR to plant files at arbitrary locations, demonstrated with a Zimbra…

Exploit implementation for Android Stagefright vulnerability CVE-2015-3864, enabling remote code execution and privilege escalation on Android 5.1.1…

Metasploit module exploiting CVE-2022-28108 in Selenium Grid for remote code execution, with content-type evasion and post-exploitation capabilities.

Proof-of-concept exploit for CVE-2021-4034 (PwnKit) demonstrating local privilege escalation in Polkit's pkexec, including patching instructions.