
CVE-2021-38297
A Proof of concept scenario for exploitation of CVE2021-38297 GO WASM buffer-overflow

A Proof of concept scenario for exploitation of CVE2021-38297 GO WASM buffer-overflow

Remote buffer overflow exploit for D-Link DIR-619L router (CVE-2024-9570) targeting the formEasySetTimezone function for penetration testing and…

Chrome V8 exploit for CVE-2019-5825 targeting version 73.0.3683.86 with --no-sandbox. Includes proof-of-concept code and integration with Metasploit…


Notepad++ RCE via config.xml commandLineInterpreter

Proof-of-concept exploit for CVE-2016-9079 targeting Firefox on Ubuntu x64, demonstrating a use-after-free vulnerability in the SVG animation…

# CVE-2026-11645 - Chrome V8 Out-of-Bounds Read/Write Exploit

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Automated exploit for CVE-2023-50643 targeting Evernote macOS via RunAsNode and enableNodeClilnspectArguments to achieve remote code execution and…

CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

CVE-2024-2961 (CNEXT) PHP file-read to RCE exploit adapted to an XXE/CTF channel

Analyzes CVE-2026-42945, an NGINX rewrite heap overrun, providing a differential detector, deterministic DoS PoC, and a credited RCE port with…

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code execution via…

Exploit used against the Netgear R6700v3 during Pwn2Own Austin 2021

对CVE-2021-29505进行复现,并分析学了下Xstream反序列化过程

Unauthenticated RCE exploit for Fantec MWiD25-DS