#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Proof-of-concept for a Self-XSS vulnerability in ChatGPTUtil, demonstrating cookie theft and account hijacking via crafted SVG payloads pasted into…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

FragAttacks WiFi penetration framework — CVE-2020-24586/87/88

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

A fork of the great TokenTactics with support for CAE and token endpoint v2

Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause,…

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Multi-purpose WiFi penetration testing toolkit for M5Stack devices. Performs network scanning, evil-twin attacks, deauthentication, captive portal…

Educational Android (Termux) toolkit for learning penetration testing, OSINT, social engineering, and network security through hands-on scripts,…

MCP server for Google search and page fetching using headless Chromium