
JYso
Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Integer overflow in FreeType software, which also affects Chrome

PoC generator and memory extraction tool for CVE-2018-16323 ImageMagick memory leak. Generates malicious XBM images to leak server memory, with…

Proof-of-concept exploit for CVE-2022-26717, a use-after-free vulnerability in Safari's WebGL implementation, enabling remote code execution via…

Proof-of-concept exploit for Spring Cloud Gateway CVE-2022-22947 that leverages Actuator SpEL injection to run arbitrary commands and deploy a…

Proof-of-concept exploit for Adobe Reader type confusion leading to heap overflow, with detailed root-cause analysis and detection guidance.

Simulated proof-of-concept for CVE-2025-2783, a Chrome Mojo IPC sandbox escape. Includes phishing delivery, memory fuzzing, IPC simulation, and…

Exploit tool for CVE-2025-5777, a Citrix NetScaler memory leak, featuring malformed request triggering, hex dump output, and async scanning for…

Deep-dive analysis and exploitation walkthrough of CVE-2016-4622, a WebKit JavaScriptCore memory disclosure vulnerability via Array.slice TOCTOU race…

Proof-of-concept exploit for CVE-2026-14382, a high-severity ANGLE vulnerability in Chromium, with 32-bit and AArch64 PoCs achieving program counter…

Proof-of-concept exploit for CVE-2013-2730, demonstrating a memory corruption vulnerability with a C-based implementation for security research and…

Proof-of-concept adaptation of CVE-2024-23222 (WebKit JSC TOCTOU) for Linux x86_64, demonstrating stale-cell UAF via DFG compiler race window with…

Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

Proof-of-concept exploit for CVE-2020-15999, a heap-buffer-overflow in Chrome's FreeType font rendering via crafted SBIX table, with ASAN crash…

Exploit for CVE-2022-22620 (Zombie): use-after-free in WebKit/Safari with infoleak of JSObject address, tested on webkitgtk-2.34.3.

Exploits pre-auth XSS in WordPress (CVE-2026-64638) to achieve RCE; includes safe-check mode, reverse shell, C2 beaconing, persistence, privilege…

Proof-of-concept exploit for CVE-2021-30573, a use-after-free vulnerability in Google Chrome's GPU component allowing remote heap corruption via…

There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP.…