
CVE-2025-32463_sudo_chroot
Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo's chroot feature via malicious NSS library loading. Includes…

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo's chroot feature via malicious NSS library loading. Includes…

Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records.

lazy way to create CVE-2023-38831 winrar file for testing

PoC for CVE-2026-12191

reproducing an old istio bug

A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5…

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite…

Reproduction lab for CVE-2023-51385: command injection in OpenSSH ProxyCommand via malicious git submodule URLs. Step-by-step guide to verify the…

Docker-based PoC environment for CVE-2018-15133 Laravel APP_KEY unserialization vulnerability. Includes exploit script to verify remote code…

A flaw was found in the Django package, which leads to a SQL injection. This flaw allows an attacker using a crafted dictionary containing malicious…

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

Deliberately vulnerable Spring Boot application using Apache Tika 3.2.1 for testing CVE-2025-54988 XXE exploitation via malicious PDF uploads.

Generates a malicious RAR archive exploiting CVE-2023-38831 to deliver a reverse shell via a crafted PDF, for ethical testing in controlled…

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

Minimal verification lab for CVE-2025-66516 (Apache Tika XXE). Generates malicious PDF payloads and validates the vulnerability by reading sensitive…

Proof-of-concept for CVE-2023-51385: demonstrates command injection via malicious git submodule URLs when cloning with --recurse-submodules,…