
Dirtypipe-exploit
Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn. a root shell. (and attempts to restore the damaged binary as well)

Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn. a root shell. (and attempts to restore the damaged binary as well)

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

Gather and update all available and newest CVEs with their PoC.

Proof-of-concept exploit for CVE-2026-2636 targeting Windows 11 23H2 x64, built with Visual Studio 2022 and Windows SDK 10.0.

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and…

Proof-of-concept exploit for CVE-2022-30333 path traversal in unRAR, generating malicious .rar files to plant payloads at arbitrary locations.…

Example payload for CVE-2022-21894

Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE

Generates malicious RAR archives exploiting a path traversal vulnerability in unRAR to plant files at arbitrary locations, demonstrated with a Zimbra…

Win32k elevation of privilege exploit for CVE-2022-21882, providing a proof-of-concept implementation targeting Windows kernel vulnerabilities.

Windows kernel exploit for CVE-2026-20820, targeting Windows 10 21H2 and Windows 11 23H2, built with Visual Studio 2022.

Proof-of-concept exploit for CVE-2026-24291 targeting Windows 10 21H2 (build 19044.6937) AMD64, developed in C# with Visual Studio 2022.

Cisco ASA Software and ASDM Security Research

Remote buffer overflow exploit with SEH overwrite for ALLMediaServer 1.6, provided as a Metasploit module targeting CVE-2022-28381.

Educational analysis of CVE-2026-31431, a Linux kernel local privilege escalation via AF_ALG AEAD in-place operation, including technical root cause,…