
CVE-2026-32945
PJSIP DNS Compression Pointer Heap OOB Read (Remote DoS)

PJSIP DNS Compression Pointer Heap OOB Read (Remote DoS)
Symbolic execution tool

Finding CVE-2022-3786 (openssl) with Mayhem

Automated reconnaissance framework with 17+ modules for subdomain enumeration, directory brute-forcing, JS/link mining, WAF fingerprinting, and…

Fault-injection-based fuzzer that mutates generator programs to produce almost-valid inputs for targets, enabling fuzzing of complex formats and…

Proof-of-concept exploit for CVE-2025-49844 targeting a Redis heap vulnerability, with GDB-assisted crash analysis and fuzzing attempts to achieve…

Demonstrating the usage of Fastrtps-DDS vulnerability CVE-2024-28231 within Ros2

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

Lightweight fuzzing of a memory snapshot using KVM

Fully dockerized Linux kernel debugging environment

AArch64 fuzzer based on the Apple Silicon hypervisor

This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.

Docker lab reproducing CVE-2026-42533, a pre-auth nginx heap overflow and info leak via two-pass capture clobbering, with PoC scripts and patched…

Aritifacts of docker env of CVE-2020-8036


ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.


CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, CVE-2026-44295 - protobuf.js