
CVE-2022-21445-for-12.2.1.3.0-Weblogic
Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup,…

Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup,…

Proof-of-concept exploit for CVE-2021-2302 targeting Oracle WebLogic Server with a deserialization-based RCE gadget chain using MVEL expression…

Java-based exploit for CVE-2024-20931 bypassing CVE-2023-21839 patch in Oracle WebLogic. Uses JNDI injection via ForeignOpaqueReference to achieve…

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

PoC demonstrating dyld as a PAC signing oracle via hand-crafted Mach-O chained fixups on arm64e, achieving controlled PAC-valid pointer writes and…

Metasploit auxiliary module for exploiting CVE-2023-21839 (WebLogic IIOP RCE) with DNS log verification. Automates remote code execution against…


Proof-of-concept exploit for CVE-2024-21182, an unauthenticated JNDI injection leading to remote code execution in Oracle WebLogic Server via T3/IIOP…

PoC for CVE-2026-9998: RCE via insecure Python pickle deserialization in a blockchain oracle, with vulnerable node simulation and exploit script.

CVE Reproduction: cve-2025-61882-oracle_ebs_rce_reproduction

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

Python exploit for Oracle WebLogic CVE-2019-2725, enabling unauthenticated remote code execution via crafted HTTP requests to vulnerable servers.

Proof of concept for Weblogic CVE-2020-2883

Exploit toolkit for CVE-2022-21350 targeting Oracle WebLogic T3 protocol with payload generation, LDAP/HTTP servers, and support for multiple JDK…

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

[CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)

Exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution via ysoserial JRMP listener.

Proof-of-concept exploit for CVE-2024-21006 targeting Oracle WebLogic Server via T3/IIOP, enabling unauthenticated remote access to critical data.