
CVE-2026-73570
Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

Proof-of-concept for CVE-2025-54320: an email bombing vulnerability in Ascertia SigningHub's Invite User API due to missing rate limiting, allowing…

Proof-of-concept exploit for CVE-2025-68645 targeting Zimbra Mail, intended for security validation and CSIRT testing. Redirects to the maintained…

Automated exploit script for CVE-2018-8581 that delegates mailbox access in Microsoft Exchange Server, enabling privilege escalation and lateral…

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

Proof-of-concept exploit for CVE-2021-33766 (ProxyToken) authentication bypass in Microsoft Exchange Server. Supports single and batch target…

Proof-of-concept exploit for CVE-2023-51764 SMTP smuggling vulnerability in Postfix, enabling email spoofing and message injection via crafted SMTP…

Proof-of-concept exploit demonstrating CSS injection and cross-site scripting (XSS) vulnerabilities in Roundcube Webmail, enabling email content…

Zero-click unauthenticated RCE exploit for FreeScout (CVE-2026-28289) via email attachment filename bypass using Unicode characters, achieving remote…

PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

Exploit for CVE-2020-14065: unlimited file upload vulnerability in Icewarp Email Server 12.3.0.1, enabling remote code execution via crafted requests.

Proof-of-concept exploit for CVE-2020-14066 targeting insecure permissions in Icewarp Email Server 12.3.0.1, enabling privilege escalation or…

Proof-of-concept exploit for CVE-2026-73570, demonstrating SMTP command injection via crafted RCPT TO header to trigger service status changes.