A Python 3 reimplementation of the classic CVE-2018-15473 OpenSSH user enumeration exploit, extended with multi-threading, wordlist support, automatic vulnerability detection, and thread-safe exploit patching.
Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing
Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online
WinRAR < 7.13 path traversal for persistency
Master's Thesis research on CVE-2021-4034 (PwnKit). Advanced exploit with 6 payload modes (shell, id, whoami, backdoor, root user, reverse shell), automated environment setup, and complete academic documentation. Portfolio piece demonstrating Linux exploit development, memory corruption analysis, and privilege escalation research.
Master's Thesis research on CVE-2025-55182 (React2Shell). Advanced exploit with 4 attack vectors, interactive shell, and complete vulnerable laboratory. Portfolio piece demonstrating security research and exploit development.
Khai thác lỗ hổng bảo mật CVE-2025-55182 trong thành phần React
Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).
CVE-2025-55182 — React2Shell
CVE-2025-52204: Reflected XSS / HTML Injection in Znuny OTRS
SSH Terrapin Attack Vulnerability Scanner (CVE-2023-48795)
Python Proof of Concept (PoC) for CVE-2026-29000: pac4j-jwt Authentication Bypass via Public Key JWE Forgery.
Langflow at pre-CVE-2025-3248 fix commit for variant analysis benchmarking
REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized environments. It sends crafted POST requests to targets, analyzes server responses for execution indicators, and supports batch scanning with custom input, structured payload handling, and clear CLI output.
dol_eval_standard() whitelist bypass eval() RCE, affecting Dolibarr 23.0.0 and below by jiva (jivasecurity.com)
Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.
Modernized ProxyShell Exploit (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207)
Exploit script for cve-2025-15467