
CVE-2018-15982
Aggressor Script to launch IE driveby for CVE-2018-15982.

Aggressor Script to launch IE driveby for CVE-2018-15982.

A minimal reproduction of an AngularJS <textarea> XSS vulnerability on IE (tracked as CVE-2022-25869).

Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT…

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

An automated, modular cryptanalysis tool; i.e., a Weapon of Math Destruction

This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7.

Aggressor Script to launch IE driveby for CVE-2018-4878

External C2 Using IE COM Objects

MS Word MS WordPad via IE VBS Engine RCE

Linux kernel hbp exploit method demo. (i.e. the degradation version of CVE-2022-42703)

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated…

Aggressor Script to just launch IE driveby for CVE-2018-4878


ImageMagick LFI PoC [CVE-2022-44268]

Little thing put together quickly to demonstrate this CVE