
CVE-2026-24688
Proof-of-concept exploit for CVE-2026-24688, a denial-of-service vulnerability in pypdf's outline parsing. Includes malicious PDF generator and…

Proof-of-concept exploit for CVE-2026-24688, a denial-of-service vulnerability in pypdf's outline parsing. Includes malicious PDF generator and…

Analyzes CVE-2024-38998, a prototype pollution vulnerability in requirejs 2.3.6, demonstrating how malicious config inputs can lead to DoS, RCE, or…

Proof-of-concept reproducers for Apache Camel camel-knative structured CloudEvent header injection (CVE-2026-63621), demonstrating header injection…

Research code & papers from members of vx-underground.

This repository provides the official implementation of POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models.

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

"A single malicious packet can own your device." — Android Security Team, Nov 2025

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo 1.9.14-1.9.17 via chroot misconfiguration and malicious NSS library…

Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.

Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and…