
CVE-2025-55891
Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…

Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…

Tool to help exploit XXE vulnerabilities

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

Zip file format fuzzer and multi-tool.

Tool to make in memory man in the middle

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

Documentation of a denial-of-service vulnerability in the Rizin reverse engineering framework's ELF parser, caused by a forged DT_VERNEEDNUM value…

Melkor is a very intuitive and easy-to-use ELF file format fuzzer to find functional and security bugs in ELF parsers.

Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

sample exploit of buffer overflow in libpng

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

Proof-of-concept exploit for CVE-2017-7374, triggering a vulnerability in ext4 filesystem encryption via crafted directory operations on Linux.