


Step-by-step walkthrough of exploiting CVE-2024-21413 in Microsoft Outlook to bypass Protected View and leak NTLM credentials via Moniker Links,…

Proof-of-concept exploit for CVE-2024-22889, an incorrect access control vulnerability in Plone CMS v6.0.9 allowing remote attackers to view and list…

Proof-of-concept exploit for CVE-2015-7214 demonstrating Same-Origin Policy bypass in Firefox 42.0 via data and view-source URIs, with local and…

Proof-of-concept exploit for SQL injection in Sourcecodester Cab Management System 1.0, demonstrating arbitrary SQL execution via the id parameter in…

Python POC for CVE-2025-5095

Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)

Builders and research notes for exploiting CVE-2026-21514 (Protected View bypass) and CVE-2026-21510 (RCE) in MS Office, including obfuscation and…

Exploit PoC for CVE-2025-53770 enabling webshell upload to SharePoint, ValidationKey extraction, signed ViewState generation, and remote code…

Proof-of-concept exploit for CVE-2024-21413, a critical Microsoft Outlook remote code execution vulnerability (MonikerLink) with CVSS 9.8, enabling…

This repository talks about Zero-Day Exploitation of Atlassian Confluence, it's defense and analysis point of view from a SecOps or Blue Team…

Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view…

Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.


It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.