
pwn2own2020
Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

基于Java实现的Shellcode加载器

Herramienta para evadir disable_functions y open_basedir

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

A simple ptrace-less shared library injector for x64 Linux

PoC Thread Execution Hijacking for Win32 Code Injection

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

it works on xp (all version sp2 sp3)


CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002

ImaegMagick Code Execution (CVE-2016-3714)

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…
