
CVE-2023-22047-Oracle-PeopleSoft-LFI
CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions

Here you can find my relation about the project I made for the Internet Security course. Because I written it in Latex, you can also find the Latex…



CVE-2025-24071 Proof Of Concept

Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in…

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

CVE-2024-34693: Server Arbitrary File Read in Apache Superset


A path traversal in smbserver.py allows an attacker to read/write arbitrary files on the server.

Remote attacker can access sensitive data exposed on the URL

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

CVE-2023-24055 PoC (KeePass 2.5x)

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…