
CVE-2014-4140
Technical notes and debugger analysis for CVE-2014-4140, a use-after-free vulnerability in MSHTML's CHtmRootParseCtx::AddText leading to remote code…

Technical notes and debugger analysis for CVE-2014-4140, a use-after-free vulnerability in MSHTML's CHtmRootParseCtx::AddText leading to remote code…

Proof-of-concept exploit for Same-Origin Policy bypass in Samsung Internet Browser for Android, demonstrating a cross-origin data access…

Proof-of-concept for a Cross-Site Request Forgery (CSRF) vulnerability in code astro Internet Banking System 2.0.0, enabling unauthorized account…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor…

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit


Spring4Shell - Spring Core RCE - CVE-2022-22965

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Aggressor Script to launch IE driveby for CVE-2018-15982.

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal

Educational lab environment with a proof-of-concept exploit for CVE-2025-49844 (RediShell), a critical use-after-free in Redis Lua interpreter,…

A PoC for CVE 2023-20198


{ Spring Core 0day CVE-2022-22963 }

UnrealIRCd 3.2.8.1 backdoor exploit — reverse shell via AB; trigger, built from scratch in Python using raw sockets. No Metasploit.

Educational lab environment demonstrating CVE-2025-49844 (RediShell) in Redis. Includes Docker setup, exploit PoC script, and security…

HostHeaderInjection-Askey