
CVE-2026-16723
Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

Educational lab demonstrating a stack buffer overflow (CVE-2025-5548) in FreeFloat FTP Server. Covers full exploit development: vulnerability…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Step-by-step demonstration of a local privilege escalation vulnerability in Lenovo PC Manager, exploiting weak file permissions on a system service…

CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…

A micro lab for CVE-2021-44228 (log4j)

Educational walkthrough for exploiting CVE-2025-68613, a critical RCE in n8n workflow automation. Covers expression injection, sandbox escape,…

Educational PoC for Dirty COW (CVE-2016-5195) with logging, ptrace fallback, and binary payload support.

Step-by-step tutorial for exploiting Log4j CVE-2021-44228 with Docker-based vulnerable app, JNDIExploit listener, and LDAP payload injection for…

Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab…

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Proof-of-concept exploit for CVE-2023-42456, demonstrating privilege escalation via sudo NSS library hijacking through chroot injection. Includes…

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

Step-by-step lab guide for exploiting CVE-2017-10271 (WebLogic XMLDecoder deserialization RCE) with manual payload construction, blind RCE bypass,…

RCE project