
CVE-2026-33829-Writeup
Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)

Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)


Proof-of-concept exploit for stored XSS and insecure permissions in Collabora CODE <= 4.2.2 via the Vereign WOPI API, enabling account hijacking and…

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

Academy LMS <= 5.10 CSRF

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

Step-by-step walkthrough of exploiting CVE-2024-21413 in Microsoft Outlook to bypass Protected View and leak NTLM credentials via Moniker Links,…

Educational demo of CVE-2025-4664, a Chrome Loader vulnerability enabling cross-origin data leakage via referrer-policy manipulation. Includes a…

Detailed proof-of-concept and technical analysis for CVE-2026-2441, a Chrome CSS use-after-free vulnerability enabling sandboxed renderer RCE via…

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

CVE-2024-21413 Açığını Kullanarak Giriş Bilgilerini Alma

Cross-Site Scripting vulnerability in Advanced REST Client v.17.0.9 exploit

Proof-of-concept exploit for CVE-2024-42008, a Cross-Site Scripting vulnerability in RoundCube webmail. Delivers XSS payloads via contact forms to…

xll windows reverse shell

Proof-of-concept for a stored XSS vulnerability in Code Astro Internet Banking System 2.0.0, demonstrating session hijacking and client-side attacks…

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

Reflected XSS vulnerability proof-of-concept for HotelDruid 3.0.7, demonstrating arbitrary JavaScript execution via the ripristina_backup parameter…

mjml-app v3.0.4 & 3.1.0-beta RCE exploit