
CVE-2026-66804-CrossDevice-Service-EoP
Proof-of-concept exploit for CVE-2026-66804, a privilege escalation vulnerability in the CrossDevice Service component.

Proof-of-concept exploit for CVE-2026-66804, a privilege escalation vulnerability in the CrossDevice Service component.

Docker-based WordPress lab reproducing CVE-2026-60137 and CVE-2026-63030 pre-auth RCE, with a Python PoC exploit for SQLi, privilege escalation, and…

GhostLock (CVE-2026-43499) exploit fork for RootMyVivo Neo — iQOO Neo 11 (PD2520, SM8750, 6.6.89). For authorized research on own devices only.

Defensive notes on CVE-2022-24637 in Open Web Analytics before 1.7.4, covering unauthenticated information disclosure, privilege escalation impact,…

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel race condition enabling unprivileged writes to read-only files and privilege…

Proof-of-concept exploit for CVE-2026-69414, a Windows Defender 0day enabling arbitrary file read as SYSTEM on all supported Windows versions.

Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combined of CVE-2026-49881 and…

Validated GhostLock CVE-2026-43499 port for NVIDIA Shield TV Pro mdarcy 9.2.4

Proof-of-concept exploit for OliveTin unauthenticated RCE (CVE-2026-30225) via insecure guest defaults and unvalidated argument types, enabling root…

Proof-of-concept exploit for CVE-2025-8110 in Gogs <=0.13.x, enabling authenticated symlink bypass to arbitrary file write as the Gogs process user,…

CVE-2026-49881, a logic issue in the InCallController class in Android 17's Telecom service that allows an unprivileged app to gain arbitrary code…

Proof-of-concept demonstrating container escape on Kubernetes via CVE-2026-31431 kernel page-cache corruption, achieving node-level code execution…

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

Proof-of-concept exploit for CVE-2026-69451, a privilege escalation vulnerability in Fastprox. Executes arbitrary commands with elevated privileges…

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

Technical write-up and proof-of-concept for CVE-2026-8069, a local privilege escalation in Acer NitroSense and PredatorSense services, exploiting a…

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…