
CVE-2026-43499-S26
Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

Provides a bash workaround script to mitigate CVE-2026-31431, preventing remote code execution via copy.fail exploit. Includes usage instructions for…

基于Java实现的Shellcode加载器

A simple ptrace-less shared library injector for x64 Linux

A third-party Gopher Assassin for the Havoc Framework.

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Repository containing exploit scripts for various CVEs, targeting web applications, binaries, and network services, suitable for penetration testing…

A Bash implementation of copyfail (CVE-2026-31431)

ASUSTOR ADM 5.1.2 vpnupload.cgi Format String & Stack Buffer Overflow RCE (CVE-2026-6643)

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

Free MP3 CD Ripper 2.6 版本中存在栈缓冲区溢出漏洞 (CVE-2019-9766),远程攻击者可借助特制的 .mp3 文件利用该漏洞执行任意代码。

CVE-2025-55182漏洞检测工具

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…