
CTFTiny
Official repository for CTFTiny

Official repository for CTFTiny

Christmas-themed CTF Advent Calendar with 12 structured challenges across binary exploitation, cryptography, reverse engineering, forensics, OSINT,…

CVE-2014-1303 (WebKit Heap based BOF) proof of concept for Linux

PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability

RTSPServer Code Execution Vulnerability CVE-2018-4013

Curated CTF writeup collection for GlacierCTF 2023 covering pwn, rev, web, crypto, and smart contract challenges with solutions and educational…

CVE-2025-6554

Proof-of-concept exploit for CVE-2023-38545, a heap buffer overflow in libcurl's SOCKS5 proxy handshake triggered via a malicious HTTP 301 redirect…

PoC exploit chain for CVE-2026-2796: SpiderMonkey WebAssembly sandbox escape (signature type confusion -> arbitrary R/W -> RCE)

Minimal JavaScript proof-of-concept for V8 engine vulnerability CVE-2026-5865, with scripts to patch and calibrate the exploit for d8.

Heap overflow PoC for CivetWeb CVE-2025-55763

PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause…

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

CVE-2025-24201 WebKit Vulnerability Detector (PoC)

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66…

An example exploit for CVE-2017-7376

Exploit for SonicWall CVE-2019-7482 stack-based buffer overflow vulnerability, enabling remote code execution on affected firewall appliances.