
CVE-2019-1010298
Proof-of-concept exploit targeting ARM TrustZone secure world, demonstrating a vulnerability in OP-TEE OS for educational and research purposes.

Proof-of-concept exploit targeting ARM TrustZone secure world, demonstrating a vulnerability in OP-TEE OS for educational and research purposes.

Local Privilege Escalation (LPE) vulnerability in Polkit - Pwnkit

CVE-2022-46152: Improper Validation of Array Index in the `cleanup_shm_refs' function.

Educational analysis of CVE-2023-4863 (libwebp heap buffer overflow) with Blue Team detection tools, static WebP scanner, defensive Java validator,…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

Detailed technical analysis and proof-of-concept exploit for CVE-2016-5195 (Dirty COW), a Linux kernel privilege-escalation vulnerability using a…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment…

CVE-2022-0185 POC and Docker and Analysis write up

Proof-of-concept exploit and detailed analysis of CVE-2022-0847 (Dirty Pipe) Linux kernel privilege escalation vulnerability, including Docker…

Educational lab for understanding Java deserialization vulnerabilities with PoC exploits for JBoss CVEs, gadget chain analysis, and a vulnerable HTTP…

Proof-of-concept exploit for CVE-2026-29923, a BYOVD privilege escalation in pstrip64.sys. Demonstrates physical memory read/write via IOCTL to steal…

Java-based research harness for studying CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization, intended for…

Detailed write-up and proof-of-concept exploit for CVE-2021-4034 (PolKit pkexec local privilege escalation), including a Docker lab environment for…

CVE-2021-3156 POC and Docker and Analysis write up

In-depth technical analysis and proof-of-concept for CVE-2024-38063, a critical Windows IPv6 kernel RCE. Includes root-cause breakdown, Scapy-based…