byte_reaper's profile picture. Exploit Developer

Byte Reaper

@byte_reaper

Exploit Developer

Pinned

A technical explanation of MTE protection in the Linux system and how it works. In this article, you will understand all the basics of tag allocation and its storage method. article : bytrep.com/Article3.html #Article #mte #linux #arm

byte_reaper's tweet image. A technical explanation of MTE protection in the Linux system and how it works. In this article, you will understand all the basics of tag allocation and its storage method.

article : bytrep.com/Article3.html
#Article #mte #linux #arm

This article provides a comprehensive analysis of the CVE-2025-39913 vulnerability in the Linux kernel's eBPF SOCKMAP component, based on detailed research of the kernel architecture and memory management mechanisms. Link : bytrep.com/Article2.html #Linux #cve #exploit #eBPF


CVE-2025-39913 (UAF): Vuln in the Linux kernel tcp_bpf_send_verdict() function. When bpf_msg_cork_bytes() fails to allocate psock->cork, the kernel may skip freeing sk_msg, leading to memory mismanagement. POC : bytrep.com/exploit39913.h… Github : github.com/byteReaper77/C… #linux


CVE-2025-11077 (SQL injection): There is a blind SQL injection in the Online Learning Management system via the title POST parameter (boolean/time‑based). Exploit : github.com/byteReaper77/C… #vulnerability #sqlinjection #sqli #blindSQLi #PoC #exploit #CVE


POC for the CVE-2025-39866 vulnerability in Linux kernel<6.12.16 It is a UAF vulnerability due to the lack of a spinlock for threads,which allows the freeing of struct WB&inode during thread execution,causing a kernel panic for the system. github.com/byteReaper77/C… @cvefeedio #cve


CVE-2025-59342 (Path Traversal): path traversal exploit for esm.sh (CVE-2025-59342). The X-Zone-Id header can be abused to write files outside the intended storage. Exploit : github.com/byteReaper77/C… #infosec #bugbounty #cve @cvefeedio #exploit


CVE-2025-10046 - SQL injection : SQL injection in ELEX WooCommerce Google Shopping (v1.4.3) has an SQL Injection in elex-manage-feed-ajax.php (file_to_delete). POC : github.com/byteReaper77/C… @cvefeedio #exploit #cve #sql #WordPressPlugins

byte_reaper's tweet image. CVE-2025-10046 - SQL injection :
SQL injection in ELEX WooCommerce Google Shopping (v1.4.3) has an SQL Injection in elex-manage-feed-ajax.php (file_to_delete).

POC : github.com/byteReaper77/C…
@cvefeedio #exploit #cve #sql #WordPressPlugins

♣️CVE-2025-9090 (command injection): command injection in Tenda AC20 16.03.08.12 (/goform/telnet) Exploit : github.com/byteReaper77/C… #cve #exploit #Cybersecurity

byte_reaper's tweet image. ♣️CVE-2025-9090 (command injection):
command injection in Tenda AC20 16.03.08.12 (/goform/telnet)
Exploit : github.com/byteReaper77/C…
#cve #exploit #Cybersecurity

♣️CVE-2025-8971 (SQL): SQL injection vulnerability in itsourcecode Online Tour and Travel Management System. Exploit : github.com/byteReaper77/C… #exploit #cve #sql #Cybersecurity


CVE-2025-8730 (hard-coded credentials) : Vulnerability in Belkin F9K1009/F9K1010 web interface allows attackers to bypass login and gain full admin access. Exploit: github.com/byteReaper77/C… #CVE #Infosec #ZeroDay #Exploit #Cybersecurity


CVE-2025-7769 (ٌRCE): Remote Command Injection via the cmd parameter in /cgi-bin/mobile_api,allowing unauthenticated attackers to execute system commands on the target device. POC : github.com/byteReaper77/C… @cvefeedio @VulnersCom #CVE #CyberSecurity #Infosec #BugBounty #ZeroDay


🔴CVE-2025-8471 (SQLi) : SQL Injection in Projectworlds Online Admission System v1.0 which causes data extraction : Exploit: github.com/byteReaper77/C… #CVE #Infosec #ZeroDay #Exploit #Cybersecurity


🔴CVE-2025-41373 (Authenticated SQL Injection) : - SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1 which allows arbitrary SQL via the `idestudio` parameter . - Exploit: github.com/byteReaper77/C… #cve #Infosec #Exploit #Cybersecurity


CVE-2025-54769 (RCE) : Directory Traversal vulnerability in LPAR2RRD leads to Remote Code Execution by abusing the upgrade.sh endpoint and CGI execution. Exploit: github.com/byteReaper77/C… #CVE #infosec #ZeroDay #Exploit #CybersecurityNews


🔴CVE-2025-8191 (XSS) A Cross-Site Scripting vulnerability in Swagger UI allowing JavaScript payload execution in the victim’s browser via the description field. - Exploit: github.com/byteReaper77/C… #CVE #XSS #Infosec #CyberSecurity #Exploit


United States Trends

Loading...

Something went wrong.


Something went wrong.