CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
Missing validation of signed_id_pk in RustDesk's relay handshake allows relay-position attackers to downgrade sessions to plaintext, intercept LoginRequest, and inject input events (MouseEvent, KeyEvent) post-authentication no password required
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project demonstrates vulnerability assessment, exploitation, mitigation, and SIEM detection for Oracle WebLogic (CVE-2017-10271) and Apache Druid (CVE-2021-25646).
CVE-2026-29000 - pac4j-jwt (< 4.5.9 / < 5.7.9 / < 6.3.3) JwtAuthenticator authentication bypass PoC
Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8
CVE-2026-51833 Advisory
CVE-2025-10035 Research writeup
☢️ ReactorWatch v3.2.1 — Nuclear Reactor Core Monitoring System Pentest | CVE-2025-55182 (React2Shell) Unauthenticated RCE → SQLite Exfil → MD5 Crack → SSH Pivot → CDP Root Escalation | CVSS 10.0 | AMN SECURITY
Altay takımı haftalık sunumu için yaptığım cve-2025-22457 zafiyeti demo uygulaması
Proof of Concept for Reflected XSS in Lucee CFML (CVE-2026-29519)
OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation
Librebooking Admin RCE PoC CVE-2026-61343
PoC for CVE-2025-55182 React2Shell
包括能执行的命令探测和一键getshell(需要服务器部署服务)
Whitehat School 4기 CVE-2021-4034 분석 및 POC 작성
Public disclosure for CVE-2026-52100 (CSRF) & CVE-2026-52101 (SSRF) in linx-server. MITRE assigned the CVEs; this repo provides a public reference and helps affected users understand the risk.
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free