
CVE-2020-14882
CVE-2020-14882

CVE-2020-14882

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

PoC for CVE-2026-9998: RCE via insecure Python pickle deserialization in a blockchain oracle, with vulnerable node simulation and exploit script.

CVE Reproduction: cve-2025-61882-oracle_ebs_rce_reproduction

Proof-of-concept exploit for CVE-2024-21182, an unauthenticated JNDI injection leading to remote code execution in Oracle WebLogic Server via T3/IIOP…

PoC demonstrating dyld as a PAC signing oracle via hand-crafted Mach-O chained fixups on arm64e, achieving controlled PAC-valid pointer writes and…

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

Proof-of-concept exploit for CVE-2024-21006 targeting Oracle WebLogic Server via T3/IIOP, enabling unauthenticated remote access to critical data.

Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup,…

Exploit toolkit for CVE-2022-21350 targeting Oracle WebLogic T3 protocol with payload generation, LDAP/HTTP servers, and support for multiple JDK…

Proof-of-concept exploit for CVE-2024-20931 targeting a remote code execution vulnerability in Oracle WebLogic Server. Includes payload generation…

Java-based exploit for CVE-2024-20931 bypassing CVE-2023-21839 patch in Oracle WebLogic. Uses JNDI injection via ForeignOpaqueReference to achieve…

Metasploit auxiliary module for exploiting CVE-2023-21839 (WebLogic IIOP RCE) with DNS log verification. Automates remote code execution against…

Exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution via ysoserial JRMP listener.

Multi-step proof-of-concept exploit for CVE-2017-1000486 (PrimeFaces EL injection) with padding oracle secret retrieval and blacklist-bypassing…

A short demo of CVE-2021-44228

Proof-of-concept exploit for CVE-2021-2302 targeting Oracle WebLogic Server with a deserialization-based RCE gadget chain using MVEL expression…

Proof-of-concept exploit for CVE-2016-3510, a Java deserialization vulnerability in Oracle WebLogic Server, demonstrating remote code execution.