
CVE-2024-39929
POC to test CVE-2024-39929 against EXIM mail servers

POC to test CVE-2024-39929 against EXIM mail servers

POC_CVE-2026-45185 for nuclei-templates

CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

Exploit for Exim4 4.93 CVE-2020-28018

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.

CRLF Email Header Injection in Plunk via raw MIME construction — CVSS 8.5

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

LetsDefend SOC336 case study on CVE-2025-21298

Proof-of-concept exploit for CVE-2020-14066 targeting insecure permissions in Icewarp Email Server 12.3.0.1, enabling privilege escalation or…

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

CVE-2026-28289

Proof-of-concept exploit for CVE-2023-23397, an Outlook/Exchange privilege escalation vulnerability that triggers NTLM credential theft via a…

ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. …

Proof-of-concept for CVE-2025-54320: an email bombing vulnerability in Ascertia SigningHub's Invite User API due to missing rate limiting, allowing…