#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

Web traffic interception simulation tool for cybersecurity research and defensive learning in isolated lab environments.

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

SeedDMS Stored Cross Site Scripting(XSS)

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

cve-2019-11510, cve-2019-19781, cve-2020-5902, cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084,…

CVE-2022-30190 | MS-MSDT Follina One Click

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation,…

Little thing put together quickly to demonstrate this CVE

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Swagger UI (CVE-2018-25031) POC, [HTMLi, XSS].

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.