
CVE-2023-24871
pocs & exploit for CVE-2023-24871 (rce + lpe)

pocs & exploit for CVE-2023-24871 (rce + lpe)

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

Proof of concept for CVE-2024-7479

My PoC of Lenovo-CVE-2025-8061

Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE



PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab,…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

open source port/reimplementation of the Cobalt Strike BOF Loader as is

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Writeup of the Oracle DSR stack buffer overflow vulnerability (DRA) CVE-2014-6598

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…