
siras
Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.


→ poc for CVE-2025-29927

DejaVU - Open Source Deception Framework

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Technical report about a critical vulnerability in Xiaomi (CVE-2024-45352)


Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

PoC and internal port brute-forcer for CVE-2023-27163

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Unauthenticated Arbitrary File Read via Absolute Path



CVE-2025-29927: Next.js Middleware Bypass Vulnerability