
allsafe-android
Intentionally vulnerable Android application.

Intentionally vulnerable Android application.

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

Decoder/encoder for Ubiquiti AirMAX wireless protocol frames; parse pcap/live captures, discover devices, scan for vulnerable firmware, craft…

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

Exploit scripts for CVE-2025-62507, a stack buffer overflow in Redis 8.2.0. Provides x86-64 and ARM64 ROP chain exploits with shellcode generation…

Rust-based PoC exploit for CVE-2025-7771 providing arbitrary read/write primitives via a vulnerable driver, with virtual-to-physical address…

Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver…

Exploit for Adobe Acrobat Reader DC heap buffer overflow (CVE-2021-39863) with ASLR/DEP bypass, including root cause analysis and reversed vulnerable…

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

Exploit for CVE-2026-3437 enabling arbitrary physical memory read/write through the vulnerable Portwell portwell.sys driver via MmMapIoSpace, for…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.