#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Read more at Medium

CVE-2023-23397 C# PoC

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

mjml-app v3.0.4 & 3.1.0-beta RCE exploit

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

POC CVE-2025-26318


Public disclosure for CVE-2025-56526 and CVE-2025-56527 — Stored XSS via unsanitized PDF content rendering and plaintext credential exposure in…