
JavaPayload
JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Security Research

listmonk’s Session Persistence After Password Reset and Password Change

cve-2023-22515的python利用脚本


Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

CVE-2025-58434 Proof of Concept

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.


Weblogic Unrestricted File Upload


PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

CVE-2019-9053 Exploit for Python 3


Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.