
Mini_httpd-CVE-2018-18778
PoC exploit for CVE-2018-18778: arbitrary file read in mini_httpd 1.29 via empty Host header, affecting IoT devices from Huawei, Zyxel, and others.

PoC exploit for CVE-2018-18778: arbitrary file read in mini_httpd 1.29 via empty Host header, affecting IoT devices from Huawei, Zyxel, and others.

Windows NT ioctl bruteforcer and modular fuzzer

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

Local reproduction lab and Nuclei template for CVE-2024-36420, an arbitrary file read vulnerability in Flowise via unsanitized fileName parameter.…

Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.

CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI

Proof-of-concept exploit for CVE-2026-8461, generating a crafted AVI file that triggers a crash in unpatched ffmpeg versions.

Fast and easy-to-use directory brute-forcer written in Go.

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

Proof-of-concept exploit for CVE-2024-22532: heap-based buffer overflow in XnView Classic 2.51.5 and NConvert 7.163 via crafted .xwd file, enabling…

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

Proof-of-concept and GLSL fuzzer for CVE-2026-9999 in Chrome's ANGLE/Metal WebGL backend, with build fingerprinting, curated shaders, and crash…

Proof-of-concept exploit for CVE-2017-7374, triggering a vulnerability in ext4 filesystem encryption via crafted directory operations on Linux.

RingWraith: CVE-2026-33150 and CVE-2026-33179 — Use-After-Free and NULL Dereference in libfuse io_uring

sample exploit of buffer overflow in libpng