


Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…


Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

Google Chrome CVE-2026-6307 PoC

Real world and CTFs exploiting web/binary POCs.

Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers

Exploit the vulnerability to execute the calculator

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Integer overflow in FreeType software, which also affects Chrome

exploit for CVE-2026-42945

Webkit exploit that give arbitrary R/W on 6.XX PS4 firmwares

Some V8 n-day exploits that I've written

CVE-2023-38831 PoC (Proof Of Concept)

PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy…