Posts

CVE-2025-10909

Stored XSS via SVG Upload Bypass in NovoSGA with PoC
$ published on September 24, 2025
CVE-2025-10909

CVE-2025-10844

Exploring Time-Based SQL Injection in i-Educar with PoC
$ published on September 23, 2025
CVE-2025-10844

CVE-2025-10845

Exploring Time-Based SQL Injection in i-Educar with PoC
$ published on September 23, 2025
CVE-2025-10845

CVE-2025-10846

Exploring Boolean-Based SQL Injection in i-Educar with PoC
$ published on September 23, 2025
CVE-2025-10846

CVE-2025-10584

Multiples Stored XSS in i-Educar via educar_calendario_anotacao_cad.php with PoC
$ published on September 17, 2025
CVE-2025-10584

CVE-2025-10372

Multiples Stored XSS in i-Educar via educar_modulo_cad.php with PoC
$ published on September 13, 2025
CVE-2025-10372

CVE-2025-10373

Stored XSS in i-Educar via educar_turma_tipo_cad.php with PoC
$ published on September 13, 2025
CVE-2025-10373

CVE-2025-9720

Stored XSS in i-Educar via /module/TabelaArredondamento/edit with PoC
$ published on August 31, 2025
CVE-2025-9720

CVE-2025-9721

Multiples Stored XSS in i-Educar via /module/FormulaMedia/edit with PoC
$ published on August 31, 2025
CVE-2025-9721

CVE-2025-9722

Multiples Stored XSS in i-Educar via educar_transferencia_tipo_cad.php with PoC
$ published on August 31, 2025
CVE-2025-9722

CVE-2025-9723

Stored XSS in i-Educar via educar_tipo_regime_cad.php with PoC
$ published on August 31, 2025
CVE-2025-9723

CVE-2025-9724

Multiples Stored XSS in i-Educar via educar_nivel_ensino_cad.php with PoC
$ published on August 31, 2025
CVE-2025-9724

CVE-2025-9738

Stored XSS in i-Educar via educar_tipo_ensino_cad.php with PoC
$ published on August 31, 2025
CVE-2025-9738

CVE-2025-9652

Multiples Stored XSS in i-Educar via educar_transferencia_tipo_cad.php with PoC
$ published on August 29, 2025
CVE-2025-9652

CVE-2025-9653

Multiples Stored XSS in i-Educar via educar_projeto_cad.php with PoC
$ published on August 29, 2025
CVE-2025-9653

CVE-2025-9531

Exploring Time-Based SQL Injection in i-Educar with PoC
$ published on August 27, 2025
CVE-2025-9531

CVE-2025-9532

Exploring Boolean-Based SQL Injection in i-Educar with PoC
$ published on August 27, 2025
CVE-2025-9532

CVE-2025-9137

Stored XSS in Scada-LTS via scheduled_events.shtm with PoC
$ published on August 20, 2025
CVE-2025-9137

CVE-2025-9138

Stored XSS in Scada-LTS via pointHierarchy/new/ with PoC
$ published on August 20, 2025
CVE-2025-9138

CVE-2025-9143

Multiples Stored XSS in Scada-LTS via mailing_lists.shtm with PoC
$ published on August 20, 2025
CVE-2025-9143

CVE-2025-9144

Stored XSS in Scada-LTS via publisher_edit.shtm with PoC
$ published on August 20, 2025
CVE-2025-9144

CVE-2025-9145

Stored XSS via SVG Upload Bypass in Scada-LTS with PoC
$ published on August 20, 2025
CVE-2025-9145

CVE-2025-8538

Multiples Stored XSS in i-Educar via /usuarios/tipos/novo with PoC
$ published on August 6, 2025
CVE-2025-8538

CVE-2025-8539

Stored XSS in i-Educar via public_distrito_cad.php with PoC
$ published on August 6, 2025
CVE-2025-8539

CVE-2025-8540

Stored XSS in i-Educar via public_municipio_cad.php with PoC
$ published on August 6, 2025
CVE-2025-8540

CVE-2025-8541

Stored XSS in i-Educar via public_uf_cad.php with PoC
$ published on August 6, 2025
CVE-2025-8541

CVE-2025-8542

Multiples Stored XSS in i-Educar via empresas_cad.php with PoC
$ published on August 6, 2025
CVE-2025-8542

CVE-2025-8543

Stored XSS in i-Educar via educar_raca_cad.php with PoC
$ published on August 6, 2025
CVE-2025-8543

CVE-2025-8544

Stored XSS in i-Educar via RegraAvaliacao/edit with PoC
$ published on August 6, 2025
CVE-2025-8544

CVE-2025-8545

Stored XSS in i-Educar via educar_motivo_afastamento_cad.php with PoC
$ published on August 6, 2025
CVE-2025-8545

TryHackMe: OSINT Challenge

Write Up of TryHackMe’s OSINT Challenge, tracing a digital footprint using real-world OSINT techniques.
$ published on February 28, 2025
TryHackMe: OSINT Challenge

Fearless Knight

Fearless Knight is a 2D action game made with Godot during the 2024 Santander Bootcamp.
$ published on July 11, 2024
Fearless Knight

Monthly Sales Report

Monthly sales report using Power BI to track trends and seasonal patterns.
$ published on March 18, 2024
Monthly Sales Report

Car Dashboard

Car sales dashboard using Power BI and Excel for regional performance insights.
$ published on January 16, 2024
Car Dashboard

iWant 2.0

iWant 2.0 is an assistive app for brazilian autistic users, built with Thunkable and featured at key academic events.
$ published on December 15, 2023
iWant 2.0

Piratefy

Piratefy is a Spotify-like web app built with web tech and hosted on AWS.
$ published on December 5, 2021
Piratefy

iWant

AAC app built with GDevelop to aid communication for autistic users.
$ published on November 12, 2021
iWant