#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

Proof-of-concept exploit for CVE-2017-5223 demonstrating arbitrary file read via PHPMailer's attachment and email content injection.
Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…

Proof of concept for CVE-2024-37383

Repository for CVE-2023-4549 vulnerability.

【Teedy 1.11】Account Takeover via XSS

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC)…

.json and .yaml files used to exploit CVE-2018-25031

CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

PoC for CVE-2025-22131

This repository presents a proof-of-concept of CVE-2024-50677


The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Cross Site Scripting on sanitization-management-system

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure