
gitread
CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

CVE-2026-46817

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Sorumluluk Reddi Kendi sorumluluğunuzda kullanın, size ait olmayan veya tarama izninizin olmadığı altyapılarda gerçekleştireceğiniz yasa dışı…

Detection for CVE-2025-53072 + CVE-2025-62481

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

Leveraging arbitrary file read to RCE on Oracle PeopleSoft

Oracle WebLogic Server (LFI)

Proof-of-concept exploit for CVE-2024-21006 targeting Oracle WebLogic Server via T3/IIOP, enabling unauthenticated remote access to critical data.

A tool to find folders excluded from AV real-time scanning using a time oracle

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

Metasploit auxiliary module for exploiting CVE-2023-21839 (WebLogic IIOP RCE) with DNS log verification. Automates remote code execution against…

Proof-of-concept exploit for CVE-2022-21306 targeting Oracle WebLogic Server. Includes multiple HTTP-based detection and exploitation scripts for…

Python-based exploit for CVE-2018-15473 enabling OpenSSH username enumeration via authentication response oracle, with single-user and wordlist modes.

Oracle WebLogic CVE-2022-21371