
pulse-secure-vpn-mitm-research
Pulse Secure VPN mitm Research - CVE-2020-8241, CVE-2020-8239

Pulse Secure VPN mitm Research - CVE-2020-8241, CVE-2020-8239

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Probes CVE-2026-0075 Android ContactsProvider side channel with a no-permission PoC, enabling root-cause analysis and patched-vs-vulnerable…

A powershell poc to load and automatically run Certify and Rubeus from memory.

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included

CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.


CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)

Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC

利用 CVE-2024-0044 Android 权限提升下载任意目标App沙箱文件。

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

Using CVE-2013-6282 to bypass Samsung kernel module authentication

POC to run system component in an untrusted-app process

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

A demonstration of how page tables can be used to run arbitrary code in ring-0 and lead to a privesc. Uses CVE-2016-7255 as an example.

Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501