

Decoder/encoder for Ubiquiti AirMAX wireless protocol frames; parse pcap/live captures, discover devices, scan for vulnerable firmware, craft…

Minimal proof-of-concept reproducer for CVE-2025-69419, a heap buffer overflow in OpenSSL's PKCS12_get_friendlyname() triggered by a crafted…

CVE-2026-42945 Nginx Rift

Local reproduction lab and Nuclei template for CVE-2024-36420, an arbitrary file read vulnerability in Flowise via unsanitized fileName parameter.…

Reproduces CVE-2026-7482 heap out-of-bounds read in Ollama GGUF loading and quantization, with differential analysis of quantized artifacts to…

Proof-of-concept for CVE-2026-33317, an out-of-bounds write in OP-TEE PKCS#11 TA, demonstrating Secure World heap corruption via a malformed…

Reproducible lab for CVE-2026-23398, a Linux kernel NULL dereference in icmp_tag_validation() triggered by ICMP Fragmentation Needed packets, causing…

PoC exploit for CVE-2025-5688: remote out-of-bounds write in FreeRTOS-Plus-TCP via crafted LLMNR/mDNS queries, causing crash or potential RCE on…

Demonstrating the usage of Fastrtps-DDS vulnerability CVE-2024-28231 within Ros2

Exploit for stack-based buffer overflow found in the conn-indicator binary in the TP-Link Archer AX50 router

Intentionally vulnerable Android application.

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Nuclei template to detect Apache servers vulnerable to CVE-2024-38473

Proof-of-concept exploit for CVE-2024-27316, an HTTP/2 CONTINUATION flood vulnerability in Apache httpd, demonstrating resource exhaustion via…

Proof-of-concept exploit for CVE-2024-22640, a ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted HTML color input, with demonstration code.

Proof-of-concept for CVE-2024-22641: ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted SVG files, demonstrating regex backtrack limit…

Proof-of-concept exploit for CVE-2024-22532: heap-based buffer overflow in XnView Classic 2.51.5 and NConvert 7.163 via crafted .xwd file, enabling…