
CVE-2023-22047-Oracle-PeopleSoft-LFI
CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions

Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in…

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…



CVE-2025-24071 Proof Of Concept

Remote attacker can access sensitive data exposed on the URL

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

CVE-2024-34693: Server Arbitrary File Read in Apache Superset

CVE-2023-24055 PoC (KeePass 2.5x)

A path traversal in smbserver.py allows an attacker to read/write arbitrary files on the server.


Here you can find my relation about the project I made for the Internet Security course. Because I written it in Latex, you can also find the Latex…

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…