
CVE-2023-6702
Chrome Renderer 1day RCE via Type Confusion in Async Stack Trace (v8ctf submission)

Chrome Renderer 1day RCE via Type Confusion in Async Stack Trace (v8ctf submission)

Proof-of-concept exploit for CVE-2024-21345, demonstrating a specific vulnerability with functional code for security testing and validation.

CVE-2020-3992 & CVE-2019-5544


Proof-of-concept exploit for CVE-2022-26717, a use-after-free vulnerability in Safari's WebGL implementation, enabling remote code execution via…

cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件

CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224

Exploiting CVE-2016-4657 to JailBreak the Nintendo Switch

Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)

Array.prototype.slice wrong alias information.

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE.

Proof-of-Concept exploits for D-Link DIR8xx routers

Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).

Demonstrates a proof-of-concept exploit for CVE-2021-43297, a deserialization vulnerability in Apache Dubbo's Hessian2 protocol, with provider and…

Proof-of-concept exploit for CVE-2021-21985, a critical remote code execution vulnerability in VMware vCenter Server, with JNI-based payload…