
CVE-2026-74939-escape-the-mac-n-cheese-box
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

Proof-of-concept exploit for CVE-2021-38001, a Chrome V8 JavaScript engine vulnerability, demonstrating remote code execution via crafted .mjs files.

Microsoft Office Onenote 2007 (CVE-2014-2815) ".ONEPKG" File Directory Traversal Vulnerability Leads to Arbitrary Code Execution

CVE-2016-2555

CVE-2016-4657 for NintendoSwitch rwx

Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).

High CVE-2024-4761 Exploit

An implementation of the CVE-2015-2153 exploit.


Educational proof-of-concept for CVE-2024-4947, a V8 Maglev type confusion, demonstrating a full chain from trigger to arbitrary code execution on a…

Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)

An exploit for CVE-2020-6418 implementing a SHELF Loader. Published as part of Tmp.0ut volume 2

Reproducer for CVE-2026-40473: Apache Camel camel-mina MinaConverter.toObjectInput unsafe deserialization (RCE over TCP/UDP)

CVE Reproduction: cve-2026-21509-office_security_bypass_reproduction

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)

Batch script exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows. Targets git, GitHub CLI, VS Code, and other Git…