
CVE-2018-18912
SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can…

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

In-depth technical analysis and proof-of-concept for CVE-2017-9822, an insecure deserialization vulnerability in DotNetNuke leading to remote code…

Educational exploit for CVE-2019-1663 targeting a stack-based buffer overflow in Cisco RV routers. Includes a Python exploit script, reverse shell…

Technical analysis and proof-of-concept exploit for a command injection vulnerability (CVE-2025-60854) in D-Link AX1500 routers, enabling…

Hands-on lab for exploiting Shellshock (CVE-2014-6271) with curl, Burp Suite, Metasploit, and reverse shells. Includes attack chain, countermeasures,…

PoC exploit for CVE-2025-14611 targeting hardcoded AES keys in Gladinet CentreStack/Triofox. Forges access tickets for unauthenticated arbitrary file…

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

Hands-on lab demonstrating Log4Shell (CVE-2021-44228) exploitation using Docker, Kali Linux, Burp Suite, and log4j-shell-poc. Designed for controlled…

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

Reverse-engineered analysis of CVE-2021-40444 exploitation via malicious Word document, OLE-object loading, ActiveX CAB download, and PE payload…

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.