Skip to content
View drkim-dev's full-sized avatar

Organizations

@redpoc

Block or report drkim-dev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
drkim-dev/README.md

header

Red Team Operator | Offensive Security Researcher

🏆CERTIFIED ACHIEVEMENTS

IdentifierDescriptionPOC
CVE-2025-62429RCE via PHP Code InjectionPOC
CVE-2026-25924RCE via Security Control BypassPOC
CVE-2026-25964Authenticated LFD via Path TraversalPOC
CVE-2026-25991Blind SSRF via Redirect BypassPOC
CVE-2026-30862Privilege Escalation in AppsmithPOC
CVE-2026-32321Time-based Blind SQL InjectionPOC
CVE-2026-40491[redpoc] Arbitrary File Write via Path TraversalPOC
CVE-2026-39310Auth Bypass in Electron Clipper API in TrilliumPOC
CVE-2026-39311SVG Upload to RCE in TriliumPOC
KVE-2025-0250Critical Session Architecture Flaw (PrivEsc)-
KVE-2025-0249Unauthorized Data Exposure Flaw-
KVE-2025-0248Transactional Integrity Logic Flaw-
KVE-2025-0142Confidential Vulnerability Research-

🧑 About Me

  • Red Team Operator (Former Military Sector)
    Conducting adversary emulation and offensive security operations to evaluate real-world attack paths and strengthen cyber defense.

  • Independent CVE Researcher
    Discovering and responsibly disclosing vulnerabilities in open-source software through independent research and deep logic analysis.

  • Co-Founder & Security Researcher at @RedPoc
    A vulnerability research group focused on collaborative zero-day hunting and technical growth.
    Our team analyzes widely used open-source software to discover CVE-level vulnerabilities and share exploitation techniques and security insights within the group.



⚔️ Arsenal



Pinned Loading

  1. CVE-2026-25924CVE-2026-25924Public

    CVE-2026-25924 | Kanboad Exploit

    PHP 2 2

  2. CVE-2026-25964CVE-2026-25964Public

    CVE-2026-25964 | Tandoor Recipes LFI

    Shell 2 1

  3. CVE-2026-25991CVE-2026-25991Public

    CVE-2026-25991 | Tandoor Recipes SSRF

    2 1

  4. CVE-2026-30862CVE-2026-30862Public

    CVE-2026-30862 | appsmith Privilege Escalation(xss)

    2 1

  5. CVE-2025-62429CVE-2025-62429Public

    CVE-2025-62429 | clipbucket RCE

    1 1