
HENlo
WebKit+Kernel exploit chain for all PS Vita firmwares

WebKit+Kernel exploit chain for all PS Vita firmwares

Some example source code for fixed IE11 sandbox escapes.

CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

webkit; but pwned

A proper well structured documentation for getting started with chrome pwning & v8 pwning

Safari 1day RCE Exploit

POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.

End-to-end Docker lab reproducing Apache log4j2 #4255 — FilteredObjectInputStream allowlist bypass via java.rmi.MarshalledObject (unfiltered…

Exploit for CVE-2024-5274, a Chrome V8 DCHECK bytecode mismatch vulnerability that provides out-of-bounds read/write primitives for browser…

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

Challenge handouts, source code, and solutions for UofTCTF 2025

PoC Exploit for VM2 Sandbox Escape Vulnerability


Proof-of-concept exploit for CVE-2021-38001, a Chrome V8 JavaScript engine vulnerability. Demonstrates exploitation via d8 shell with a malicious…