
cve-2026-6471-postgres-logical-decoding-dlopen
Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

OliveTin is a self-hosted web UI for exposing predefined shell commands to end users. This repository contains a proof-of-concept demonstrating two…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Proof-of-concept exploit for CVE-2025-32434, a pickle deserialization vulnerability in PyTorch's weights_only mode, demonstrating malicious tar file…

Exploit for CVE-2026-40003, an arbitrary memory write vulnerability in ZXIC/Sanechips ZX297520V3 SoC BootROM, enabling code execution via USB…

Python exploit for CVE-2024-3829 targeting Qdrant snapshot import/export, enabling file read, file write, and reverse shell execution via symlink…

A technique of hiding malicious shellcode via Shannon encoding.

Proof-of-concept exploit for CVE-2025-27591, demonstrating a binary vulnerability and providing a buildable Go exploit for security testing.

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

Poc for CVE-2026-20980, CVE-2026-20981, CVE-2026-20982

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

More examples using the Impacket library designed for learning purposes.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

A workshop about Malware Development

A rust library that allows you to host the CLR and execute dotnet binaries.

Xenotix Python Keylogger for Windows.

PoC and analysis for CVE-2022-26809, a Windows RPC runtime integer overflow vulnerability. Includes trigger scripts using PetitPotam-style UNC path…

Flash Exploit Poc