
publications
Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

The detection of internal security controls at a company

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…


Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

CVE-2026-25049


A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)

Test for CVE-2000-0649, and return an IP address if vulnerable

Script fo testing CVE-2000-0649 for Apache and MS IIS servers

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes

The code for personally reproducing the corresponding vulnerability