
CVE-2024-32002-POC
PoC for CVE-2024-32002: RCE via malicious git submodule hooks on case-insensitive filesystems

PoC for CVE-2024-32002: RCE via malicious git submodule hooks on case-insensitive filesystems

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing


"A single malicious packet can own your device." — Android Security Team, Nov 2025

Research code & papers from members of vx-underground.

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

Low Interaction Mobile Honeypot

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

Proof-of-concept reproducers for Apache Camel camel-knative structured CloudEvent header injection (CVE-2026-63621), demonstrating header injection…

Technical proof-of-concept and deep-dive analysis of CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol via path traversal, fake…

Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527

Critical Vulnerability (9.8) - RecordedFuture Triage dynamic analysis engine can fail to record malicious behavior when samples produce very…

Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…