


PoC code for CVE-2017-13253

CVE-2020-13942 unauthenticated RCE POC through MVEL and OGNL injection

Quicky serve files over http or https using flask.

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)

A fully public exploit of the CVE-2020-0022 BlueFrag Android RCE Vulnerability (tested on Pixel 3 XL)

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers

[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization

CVE-2024-49112 LDAP RCE PoC and Metasploit Module


The offical exploit for Pandora v7.0NG Post-auth Remote Code Execution CVE-2019-20224

GiveWP PHP Object Injection exploit

Exploit PoC for CVE-2026-31431 that uses AF_ALG and splice() to overwrite Linux page cache and patch /usr/bin/su in memory, escalating unprivileged…


Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts

Atlassian Jira unauthen template injection