
CVE-2016-2334
Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

CVE-2026-39154, Stored XSS in CometChat JS SDK

Chrome V8 RCE exploit for CVE-2021-30632 targeting Windows systems. Tested on Chrome 91-93. Includes JS POC and in-the-wild bug analysis reference.

Test repository demonstrating a proof-of-concept for CVE-2021-23410 in msgpack, analyzing whether the reported deserialization vulnerability is…

Safari XSS (CVE-2017-7038) https://support.apple.com/en-us/HT207923

JS Archive List <= 6.1.5 - Unauthenticated SQL Injection

JS Job Manager < 1.1.9 - Unauthenticated Arbitrary Plugin Installation/Activation

CVE-2018-6389 PoC node js multisite with proxy

Haraj Script 3.7 - Authenticated Stored XSS

Technical documentation and proof-of-concept for CVE-2025-63700, an OAuth authentication bypass vulnerability in Clerk-js 5.88.0 allowing…