
CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer
PoC and internal port brute-forcer for CVE-2023-27163

PoC and internal port brute-forcer for CVE-2023-27163

A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)

Unauthenticated Arbitrary File Read via Absolute Path

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…


A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an…

Tool to discover external and internal network attack surface

Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes


Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…


There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions …