
CVE-2026-17544
Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Palo Alto - CVE-2026-0300 exploit

Collection of proof-of-concept exploit scripts for known CVEs targeting Linux kernels, Windows drivers, browsers, and web apps, for security research…

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

NGINX RCE exploits

PoC for CVE-2026-65650 - Elgg avatar upload DoS

Reproduction of cve-2025-0282-ivanti_rce_reproduction

Reproduction toolkit for CVE-2025-5777 (CitrixBleed 2) memory disclosure vulnerability in Citrix NetScaler ADC/Gateway. Includes PoC, affected…

Curated archive of public proof-of-concept exploits and vulnerability research writeups covering web, binary, and network security, with a focus on…

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

Google Chrome CVE-2026-6307 PoC

Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE


POC for CVE-2025-29384

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)
