
CVE-2025-28073
Proof-of-concept for a reflected XSS vulnerability in phpList 3.6.15 via the /lists/dl.php endpoint, enabling session hijacking and arbitrary…

Proof-of-concept for a reflected XSS vulnerability in phpList 3.6.15 via the /lists/dl.php endpoint, enabling session hijacking and arbitrary…

In this project, we found a recent attack through the malicious container and implemented a security mechanism to stop it.

Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN

CVE-2020-12625: Cross-Site Scripting via Malicious HTML Attachment in Roundcube Webmail

Python proof-of-concept for testing SMTP command injection (CVE-2026-73570) by sending malformed RCPT TO addresses to detect shell command…

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

CVE-2026-77818 - Yordam Kütüphane Otomasyon Sistemi - Üç ayrı noktada yansıtılmış HTML enjeksiyonu, form action ele geçirme ve kimlik bilgisi…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3

Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions

Python exploit script and Nuclei template for CVE-2023-37979, a reflected XSS vulnerability in the Ninja-forms WordPress plugin, enabling automated…