
CVE-2025-1015
an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Erstellt gefälschte Authentifizierungsabfrage, um Klartext-Passwörter von Benutzern zu erfassen


Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

Eine automatisierte Angriffskette basierend auf CVE-2022-30190, einer E-Mail-Backdoor und Bildsteganografie.

Trojaner CVE-2024-28085 CVE 28085

Remote-DLL-Hijack-Exploit für Real Player (CVE-2022-32291), der bösartige DLLs von WebDAV/SMB-Freigaben verwendet, um Codeausführung zu erreichen.

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Penetrationstest-Labor zur Demonstration der Moniker-Link-Ausnutzung von CVE-2024-21413 für den Diebstahl von NTLM-Anmeldeinformationen,…

Bildungsbezogenes Cybersicherheitsprojekt, das die Ausnutzung und Eindämmung von CVE-2020-25213 (WordPress File Manager Plugin RCE) demonstriert.…

Winrar-Exploit CVE-2023-38831

Das Ziel von Axiom ist es, eine vollständig anonyme, dezentrale und zensurresistente Social-Media-Plattform bereitzustellen. Um dies zu ermöglichen,…

a SET framework templates

SEt framework

Metasploit-basiertes Tool zum Einbetten von PDF-Backdoors, das CVE-2010-1240 ausnutzt, um Meterpreter-Payloads mittels Social Engineering für…

Proof-of-Concept-Exploit für CVE-2018-13257, der Host-Header-Spoofing in Blackboard Learn demonstriert, um Benutzersitzungen über eine bösartige…

WordPress Munk Sites Plugin <= 1.0.7 - CSRF zu beliebiger Plugin-Installation Schwachstelle

Dieses Projekt enthält ein Python-Skript, das **CVE-2023-38831** ausnutzt, eine Schwachstelle in **WinRAR**-Versionen vor 6.23. Der Exploit erzeugt…