
CVE-2020-14882-WebLogic-Analysis
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

Local file inclusion exploitation tool

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…



Toolbox containing research notes & PoC code for weaponizing .NET's DLR

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

A PoC Java Stager which can download, compile, and execute a Java file in memory.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.