
CVE-2026-9999-exploit
Proof-of-concept and GLSL fuzzer for CVE-2026-9999 in Chrome's ANGLE/Metal WebGL backend, with build fingerprinting, curated shaders, and crash…

Proof-of-concept and GLSL fuzzer for CVE-2026-9999 in Chrome's ANGLE/Metal WebGL backend, with build fingerprinting, curated shaders, and crash…

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…

Proof-of-concept exploit chain for Firefox JIT CVE-2026-2764, chaining JIT miscompilation and use-after-free into arbitrary read/write and WASM…

CVE-2020-8248: Privilege Escalation via Zip Wildcard Exploit in Pulse Secure VPN Linux Client


PoC CVE-2020-6308

Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)


Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

Wing FTP Server 6.2.5 - Privilege Escalation


Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

phpMyAdmin XSS

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header…

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate