
CVE-2025-4796
Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).



CVE-2023-5561-PoC

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

An automated SMB relay exploitation script.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Python script to create a message with the vulenrability properties set

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

CVE 2020-1472 Script de validación

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…