
CVE-2019-2725
Python-based exploit for CVE-2019-2725 (Oracle WebLogic) providing command execution and webshell upload targeting versions 10.3.6 and 12.1.3.

Python-based exploit for CVE-2019-2725 (Oracle WebLogic) providing command execution and webshell upload targeting versions 10.3.6 and 12.1.3.

Oracle E-BS CVE-2022-21587 Exploit

Batch vulnerability scanner for CVE-2018-2628 in Oracle WebLogic, with configurable timeout and IP list input for automated detection.

Java-based exploit for CVE-2020-14645 targeting Oracle WebLogic T3 protocol with JNDI injection for remote code execution.

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

Proof-of-concept exploit for CVE-2016-3510, a Java deserialization vulnerability in Oracle WebLogic Server, demonstrating remote code execution.

Python-based proof-of-concept exploit for CVE-2020-2883 targeting Oracle WebLogic Server with command execution capabilities.

Exploit for CVE-2019-2725 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution for penetration testing and…

Proof-of-concept exploit for CVE-2024-20931 targeting a remote code execution vulnerability in Oracle WebLogic Server. Includes payload generation…

Python-based exploit for CVE-2018-2628 targeting Oracle WebLogic Server, providing vulnerability detection and remote shell access via JSP payload…

Proof-of-concept exploit for CVE-2025-61882: unauthenticated remote code execution via insecure deserialization in Oracle BI Publisher integration…

Automated Oracle CVE-2014-6577 exploitation via SQLi

Proof-of-concept exploit for CVE-2022-21306 targeting Oracle WebLogic Server. Includes multiple HTTP-based detection and exploitation scripts for…

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

Exploit for CVE-2019-2890 targeting Oracle WebLogic Server via XXE injection and deserialization, enabling remote code execution through crafted…

Exploit for CVE-2018-2628, a Java deserialization vulnerability in Oracle WebLogic Server, enabling remote code execution.