
POC-CVE-2018-4411
Proof-of-concept exploit for CVE-2018-4411, demonstrating a specific vulnerability in Apple software. Intended for security testing and educational…

Proof-of-concept exploit for CVE-2018-4411, demonstrating a specific vulnerability in Apple software. Intended for security testing and educational…

Proof-of-concept exploit for CVE-2023-21608, a Use-After-Free vulnerability in Adobe Acrobat Reader enabling remote code execution via crafted PDF…

Foxit PDF Reader Remote Code Execution Exploit


PoC for CVE-2018-18500 - Firefox Use-After-Free

Demo project how to bypass the disable_functions security control of PHP on Linux

Full-chain Chrome exploit targeting CVE-2019-5782 and CVE-2019-13768 with custom ROP gadgets and shellcode for arbitrary command execution on Windows…

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

ChakraCore exploitation techniques

m-y-mo: https://github.com/github/securitylab/tree/main/SecurityExploits/Chrome/v8/CVE-2021-30632

Proof-of-concept exploit for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader and PhantomPDF, enabling remote code execution via a…

Proof-of-concept exploit for Foxit Reader CPDF_Object use-after-free remote code execution vulnerability (CVE-2018-9951) affecting versions…

Curated archive of public proof-of-concept exploits and vulnerability research writeups covering web, binary, and network security, with a focus on…

NGINX RCE exploits

Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.
