#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE
POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

cve-2024-21413

Proof-of-concept exploit generator for reflected XSS in STIG Manager OIDC authentication, enabling session token theft via crafted callback URLs and…

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Spoof file icons and extensions in Windows

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…

This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln

Stored XSS exploit for Roundcube Webmail ≤1.6.6 (CVE-2024-42009) with zero-click email exfiltration via CSS animation event handlers. Includes SMTP…

CVE-2024-42009 Proof of Concept

An active cyber defense & honeypot system for OpenWrt routers running from a USB drive.

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

Xss injection, WonderCMS 3.2.0 -3.4.2

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

CVE-2018-25031 tests