
CVE-2024-44258
CVE-2024-44258

CVE-2024-44258


Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Proof-of-concept for a stack-based buffer overflow in FortiWeb, demonstrating unauthenticated remote code execution via crafted HTTP requests when…

CVE-2018-4343: Proof-of-concept for a use-after-free in the GSSCred daemon on macOS and iOS.

Android LPE exploit for CVE-2026-43499 targeting OPPO PMG110 (kernel 6.6). Uses futex PI UAF to gain root and install a su daemon via LD_PRELOAD.

Technical analysis of the cPanel/WHM auth bypass

CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using…

These detection scripts are property of the SECPlayground Platform. Two safe detection scripts. Neither drives the close_notify-mid-BDAT trigger, so…

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.

Android netd vulnerability analysis and exploitation research for CVE-2023-40084, focusing on the platform's network daemon.

One IPv6 ND option with length zero. One missing check. Daemon walks backward and lives in the loop. Reported to OpenBSD, fixed, CVE assigned.

POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon

CVE-2018-4280: Mach port replacement vulnerability in launchd on macOS 10.13.5 leading to local privilege escalation and SIP bypass.

Exploits a TOCTOU race in PackageKit's transaction handler to install arbitrary packages as root, achieving local privilege escalation and a SUID…

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of…

Python exploit for CVE-2022-42475 heap overflow in Fortinet SSLVPN daemon. Delivers reverse shell via pwntools with customizable target, port, and…