
CVE-2021-43032
Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Post authenticated stored-xss in XenForo versions ≤ 2.2.7


Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

【Teedy 1.11】Account Takeover via XSS

An exploitation demo of Outlook Elevation of Privilege Vulnerability


All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).

CVE-2021-1675: ZERO-DAY VULNERABILITY IN WINDOWS PRINTER SERVICE WITH AN EXPLOIT AVAILABLE IN ALL OPERATING SYSTEM VERSIONS

A simple POC (CVE-2018-25031

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

Template Injection in Email Templates leads to code execution on Jira Service Management Server

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)