
CVE-2023-38831-POC
Proof-of-concept demonstrating CVE-2023-38831, a WinRAR path traversal vulnerability, by crafting a malicious ZIP archive that executes arbitrary…

Proof-of-concept demonstrating CVE-2023-38831, a WinRAR path traversal vulnerability, by crafting a malicious ZIP archive that executes arbitrary…

C++ implementation of CVE-2025-8088 WinRAR exploit using Alternate Data Streams to drop payloads into Windows Startup folder for persistence.

Exploit For: CVE-2024-42845: Remote Code Execution (RCE) in Invesalius 3.1

OS Command Injection Vulnerability via Cache Clearing Scheduler in Reolink Desktop Application

A POC exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower

Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Proof-of-concept exploit for Microsoft Office security feature bypass (CVE-2026-21509). Generates malicious DOCX files with embedded OLE objects to…

Proof-of-concept for CVE-2026-2441, a use-after-free in Chrome's CSS engine, demonstrating renderer crash and potential sandboxed code execution via…

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Exploit for CVE-2026-21509, a Microsoft Office OLE validation bypass using a speculative race-condition technique to evade AMSI/EDR and achieve code…

Proof-of-concept exploit for CVE-2026-20841, a remote code execution vulnerability in Windows Notepad, demonstrating file-based trigger and execution…

Proof-of-concept exploit for Apache PDFBox path traversal vulnerability (CVE-2026-23907), demonstrating arbitrary file write via malicious PDFs with…

PoC de CVE-2026-3502: hijacking de actualizacion en TrueConf Client para RCE (Operacion TrueChaos).

CVE-2024-7965是Google Chrome浏览器中V8 JavaScript引擎的一个高危漏洞。该漏洞源于V8引擎在处理特定JavaScript代码时实现不当,导致堆内存损坏。攻击者可通过诱导用户访问包含特制JavaScript的恶意网页,利用此漏洞在Chrome渲染器中执行任意代码。

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A DTrace on Windows Reimplementation