
Hamed Kohi
Biography
My name is Hamed Kohi, an Afghan-Canadian cybersecurity professional specializing in vulnerability research, programming and penetration testing.
I’m driven by a passion for uncovering and responsibly disclosing vulnerabilities in open-source systems,
bolstering global cybersecurity efforts.
Since starting my journey in Kabul, Afghanistan in 2020, I’ve honed my skills after moving to Canada in 2022.
Here, I’ve dived deep into vulnerability analysis, exploit development, and red team operations,
mentoring aspiring researchers and delivering innovative security solutions.
My work reflects a commitment to collaboration, continuous learning, and pushing the boundaries of cybersecurity excellence.
Certifications
- Certified Penetration Testing Specialist (CPTS, pending)
- Certified Red Team Operator (CRTO, pending)
- Virtual Hacking Labs Certified (VHL+)
- Virtual Hacking Labs Advanced+ Certified
Common Vulnerabilities & Exposures (20x CVEs)
- CVE-2024-57601 (Stored XSS & PE, EasyAppointments)
- CVE-2024-57602 (CWE-307, EasyAppointments)
- CVE-2024-57603 (Login Bruteforce, ezBookkeeping)
- CVE-2024-57604 (OTP Bruteforce, ezBookkeeping)
- CVE-2024-57605 (Stored XSS, FuelCMS)
- CVE-2025-24854 (Stored XSS, Apache JSPWiki)
- CVE-2025-29868 (Privacy Leak, Apache Answer)
- CVE-2025-47939 (Unrestricted File Upload, Typo3 CMS)
- CVE-2025-45892 (XSS, OpenCart E-Commerce)
- CVE-2025-45893 (XSS, OpenCart E-Commerce)
- CVE-2025-8520 (SSRF, Vvveb CMS)
- CVE-2025-8518 (Code Injection, Vvveb CMS)
- CVE-2025-8521 (XSS, Vvveb CMS)
- CVE-2025-8519 (Internal File Read, Vvveb CMS)
- CVE-2025-9001 (Buffer Overflow, Lemon OS)
- CVE-2025-8976 (Cross-site scripting, Vvveb)
- CVE-2025-8975 (Cross-site scripting, Vvveb)
- CVE-2025-8772 (Server-side request forgery, NukeViet)
- CVE-2025-10254 (XSS, OnlyOffice)
- CVE-2025-10255 (XSS, OnlyOffice)
Cyber Missions
-
Mission Cyber Sentinel (Completed)
A global cyber mission that resulted in securing 446,000+ digital assets; see [delta.cyberm.ca] for results. -
Cyber Mounties Canada (Completed)
A mission to build Canada's first multi-lingual, industry-approved & hands-on cybersecurity training platform; see [cyberm.ca].
Open-Source Projects
- Zerodayf (Zeroday Factory)
Core Skills
- Vulnerability Research & Development
- Desktop Application Development
- Full-Stack Web Development
- Malware Development
- Penetration Testing
Programming Languages
- C 11
- C# 10.0 and 7.3
- PowerShell
- Python 3
- JavaScript