
CVE-2026-28609-matroska-pcm-oob
Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

Race reproducer and stress toolkit for CVE-2026-52910, a Linux kernel use-after-free in reuseport cBPF selector programs, with dmesg and leak checks.

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

PIrateRF transforms your Raspberry Pi Zero W into a portable RF signal generator that spawns its own WiFi hotspot. Control everything from FM…

#INFILTRATE19 raptor's party pack.

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

QEMU-based lab for reproducing CVE-2022-46395 race condition in Arm Mali r36p0 GPU driver. Includes PoC, build scripts, and initramfs packaging for…


A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

Go Web Application Penetration Test

Educational repository demonstrating CVE-2023-4863 exploitation in libwebp using AFL++ fuzzing, with step-by-step video walkthroughs for…

Collection of CVE(work) on tenserflow binary pwning it

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…