
CVE-2023-0045
PoC and write-up for CVE-2023-0045: bypasses Linux prctl/seccomp Spectre-BTI mitigations using BTB poisoning and Flush+Reload to leak process secrets.

PoC and write-up for CVE-2023-0045: bypasses Linux prctl/seccomp Spectre-BTI mitigations using BTB poisoning and Flush+Reload to leak process secrets.

Demonstrates CVE-2022-34301 Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi), using the mm command to nullify gSecurity2 and load…

Proof-of-concept exploit for CVE-2021-3972, demonstrating UEFI firmware variable manipulation to disable Secure Boot and change legacy boot settings.

Technical advisory and proof-of-concept for a stack-based buffer overflow (CWE-121) in the NXP moal.ko Wi-Fi kernel driver, enabling local kernel…

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

CVE-2026-11499

jump over aslr attacking branch predictors to bypass aslr Technique

CVE Realtek SD card reader. CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40432, CVE-2024-40431

CVE-2016-7608: Buffer overflow in IOFireWireFamily.

Exploit and research repository analyzing CVE-2025-60013, a critical HSM initialization vulnerability enabling Bitcoin private key recovery via…

Disclosure for CVE-2025-63602, including a PoC for use of an insecure driver in Awesome Miner 11.2.4 leading to arbitrary kernel read/write to MSRs,…

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

RMASmoke main repo. CVE-2025-1122

Proof of Concept of CVE-2025-48507. The security flaw can be leveraged by Non-Secure software (e.g., Linux) to break Trust Zone and gain access to…

Public disclosure for CVE-2026-43655 AppleM2ScalerCSCDriver use-after-free

Technical details and publication about CVE-2026-38698 and CVE-2026-38699

Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

Conceptual PoC for CVE-2025-54328, a critical zero-click stack buffer overflow in Samsung Exynos baseband firmware's SMS RP-DATA parser, enabling…