
LCSAJdump
An ML powered Graph-Based Multi-Architecture Approach for ROP Gadget Detection

An ML powered Graph-Based Multi-Architecture Approach for ROP Gadget Detection

Exploit for CVE-2022-22965 (Spring4Shell) targeting Spring Framework versions vulnerable to remote code execution via classLoader manipulation.

Proof-of-concept exploit for CVE-2025-69515 demonstrating static GPS spoofing on JXL 9-inch Android infotainment units via SDR-based signal…


A reverse engineering framework written in Python.

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Frida-based .NET Framework injector and managed method hooking toolkit for runtime tracing, native entrypoint resolution, and dynamic analysis of…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Android deeplink misconfiguration detector and exploitation tool

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

Showcase of overridding the Spring Framework version in older Spring Boot versions

LLVM based static binary analysis framework

(CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Static Go proof-of-concept for CVE-2026-31431, leveraging Linux AF_ALG and splice(2) to trigger the vulnerability. Provides prebuilt binaries for…

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

Minimal 587-byte static ELF exploit for CVE-2026-31431, achieving local privilege escalation via AF_ALG splice page cache corruption. No libc or…

Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions