
CVE-2026-36130
Proof-of-concept demonstrating a vulnerability that disables Microsoft Defender (MsMpEng.exe) by locking a folder and rebooting, with screenshots…

Proof-of-concept demonstrating a vulnerability that disables Microsoft Defender (MsMpEng.exe) by locking a folder and rebooting, with screenshots…

A lib that allows using mhyprot2 driver for enum process modules, r/w process memory and kill process.

A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.

PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via…

Proof-of-concept for CVE-2026-31431 demonstrating live process code injection via page cache, achieving arbitrary code execution in a running process…

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

ASUS DriverHub Driver Update Process TOCTOU Vulnerability Leading to LPE

Proof-of-concept demonstrating command injection via shell() expansion in parameter defaults of Intake catalogs, with exploit YAML and reproduction…

Kernel Process Termination Tool ( CVE-2026-0828 exploit)

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

Proof-of-concept for CVE-2025-60349, demonstrating arbitrary process termination via IOCTL 0x22E044 to the pxscan.sys driver, causing denial of…

Proof-of-concept exploit for CVE-2026-3796, demonstrating arbitrary process termination via a vulnerable QAX driver. Includes usage instructions and…

The PoC of information disclosure in Microsoft Desktop Windows Management.

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Proof-of-concept demonstrating a Node.js permission model bypass (CVE-2026-21636) that allows network access via undici/fetch to local services,…

iOS app to check device compatibility with CVE-2021-30937 vulnerability, displaying alerts and popups during the process.

Playground for demonstrating the exploitation process of CVE-2021-37975, providing a hands-on environment for security researchers to understand and…