
rcekit
RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Proof-of-concept exploit for CVE-2026-24688, a denial-of-service vulnerability in pypdf's outline parsing. Includes malicious PDF generator and…

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…


CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

CVE-2020-36109 PoC causing DoS

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Generic Scanner for Apache log4j RCE CVE-2021-44228

Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…

Fixed Docker build for CVE-2023-20052 ClamAV XXE exploit. Resolves OpenSSL 3.0 compilation errors using Ubuntu 18.04 with OpenSSL 1.0 for…

sample exploit of buffer overflow in libpng

Proof-of-concept exploit for CVE-2017-9096 demonstrating XML External Entity (XXE) injection in iText PDF library via malicious XMP metadata and form…

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

Step-by-step guide to exploiting a stack-based buffer overflow in HexChat (CVE-2016-2233) with a malicious IRC server, including a patch to fix the…

Proof-of-concept exploit for CVE-2013-3664: heap overflow in SketchUp BMP RLE4 texture parsing enabling arbitrary code execution via malicious .skp…