Cybersecurity Engineer at T-Mobile
CVE-2025-20281-2-Cisco-ISE-RCE. Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API
21CVE-2025-62215_Windows_Kernel_PE. This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM. The exploit uses multithreaded handle manipulation and heap spraying to trigger the flaw under controlled conditions.
15CVE-2025-6543_CitrixNetScaler_PoC. Multi-host, multi-port scanner and auditor for CVE-2025-6543-affected NetScaler devices. Supports SNMP and SSH enumeration with optional CSV reporting and exploit stubs.
5CVE-2025-2945_PgAdmin_PoC. pgAdmin Proof of Concept
3CVE-2024-21762_FortiNet_PoC. Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
2CVE-2025-1302_jsonpath-plus_RCE. PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.
1CVE-2025-32463_Sudo_PoC. PoC for CVE-2025-32463: Local privilege escalation in sudo via --chroot. Exploits NSS module injection through crafted chroot environments. Designed for security researchers and lab-only environments.
1CVE-2025-31324_PoC_SAP. Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
1