
CVE-2021-41649
Proof-of-concept exploit for CVE-2021-41649 demonstrating unauthenticated SQL injection in online-shopping-system via the cat_id parameter, with…

Proof-of-concept exploit for CVE-2021-41649 demonstrating unauthenticated SQL injection in online-shopping-system via the cat_id parameter, with…

Proof-of-concept exploit for unauthenticated SQL injection in Online-Food-Ordering-Web-App, demonstrating login bypass and error/time-based blind…

Blind SQL Injection to RCE in a PHP open source application

Learning Exploit Development for Web. POCs for CVEs which was assigned to me.

A modern vulnerable web app

Writeup of a Denial of Service vulnerability in the vBulletin 3.8.7 friends list.

Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.


Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

PoC, Hunting React2Shell about CVE-2025-55182

CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server…