
Kimai-CVE-2026-49865-POC
PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Analysis of state-sponsored WhatsApp phishing infrastructure with real-time QR hijacking and device surveillance

OSINT investigation uncovering coordinated escort listing networks using shared phone infrastructure, identity rotation, and cross-platform analysis.

Automated OSINT tool for phone number discovery, pattern detection, and cross-platform correlation.

A lightweight aviation intelligence tool that queries ADSB-Exchange flight data using tail numbers or ICAO identifiers to quickly profile aircraft…


Suite de herramientas que sacan partido del CVE-2017-9097 (+RCE)

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

CVE-2025-24071 Proof Of Concept


Remote attacker can access sensitive data exposed on the URL

CVE-2023-23397 C# PoC

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

React2Shell Exploitation Tool (CVE-2025-55182)


PoC, Hunting React2Shell about CVE-2025-55182