
cve-2025-66398
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

exploitdb // The official Exploit-Database repository

The Browser Exploitation Framework Project

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.


A complete Android ImGui menu template project.

Voron messenger crypto/protocol library (X3DH-lite + Double Ratchet, group sender-keys, onion transport) — external review requested


Windows User-Mode Shellcode Development Framework (WUMSDF)

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

Reproducer for CVE-2026-33453: Apache Camel camel-coap header injection to RCE via camel-exec

Reproducer for CVE-2026-27172: Apache Camel camel-consul ConsulRegistry Java deserialization (RCE)