
gitread
CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

A tool to find folders excluded from AV real-time scanning using a time oracle

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Demonstrates command injection vulnerabilities in RayVentory Scan Engine's rvia tool, allowing arbitrary command execution via getconfig, upload,…

Exploit for CVE-2024-21006 targeting Oracle WebLogic Server LDAP injection vulnerability. Requires JNDIExploit service and specific JDK version for…

Verified PoC and analysis for CVE-2026-21962, an access-control bypass in Oracle HTTP Server/WebLogic Proxy Plug-in via URI normalization…

Unauthenticated remote code execution exploit for Oracle WebLogic Server (CVE-2019-2725) via deserialization in AsyncResponseService, delivering a…

Proof-of-concept exploit for CVE-2026-21962, a critical path traversal vulnerability in Oracle OHS and WebLogic Server proxy plugins leading to…

Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability

CVE-2026-21962

Unauthenticated authentication bypass and remote code execution exploit for Oracle WebLogic Server, targeting CVE-2020-14882 and CVE-2020-14750.

CVE Reproduction: cve-2025-61882-oracle_ebs_rce_reproduction

Exploit for CVE-2025-61882, a critical pre-auth RCE in Oracle E-Business Suite. Combines SSRF, CRLF injection, HTTP smuggling, and XSLT injection for…


Generates detection artifacts for Oracle E-Business Suite CVE-2025-61882 by serving a reverse shell payload to verify pre-auth RCE.

Java-based exploit for CVE-2023-21839 targeting Oracle WebLogic Server versions 12.2.1.3.0 and 12.2.1.4.0 via LDAP injection for remote code…