Security Researcher & Exploit Developer
Blog · Twitter · LinkedIn · Ko-fi
- CVE-2026-29059 - Windfall: unauth RCE in Windmill & Nextcloud Flow via path traversal + credential leak + PostgreSQL heap dump + Nextcloud AppAPI takeover - Referenced by CERT-FR & BSI (writeup · toolkit · CERT-FR · BSI)
- CVE-2025-2611 - ICTBroadcast unauth RCE via cookie injection - Added to VulnCheck KEV (writeup · KEV)
- CVE-2025-34147 to 34152 - 6 unauth command injections in Aitemi M300 WiFi Repeater - Referenced by CERT-FR (writeup · CERT-FR)
- CVE-2026-39912 - Unauth account takeover in Xboard & V2Board via magic link token leak (7000+ instances) (writeup · exploit)
- CVE-2026-28515 to 28517 - 3 chained vulns in openDCIM: missing auth + SQLi + command injection = unauth RCE (writeup)
- CVE-2026-27174 to 27181 - 8 vulns in MajorDoMo: 3 critical RCE, SQLi, 3 XSS (writeup)
- CVE-2024-22899 to 22903 - Exploit chain in Vinchin Backup & Recovery (exploit)
All CVEs
- cewlai - AI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
- pik - Exploit framework & SDK for Go
- pgread - Dump PostgreSQL data from heap files without credentials
- wpprobe - Fast WordPress plugin enumeration (800+ stars, in Kali Linux)
- LFIHunt - Scan & exploit Local File Inclusion
- msf-exploit-collection - All my Metasploit modules in one place




