
CVE-2026-54433
Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Lateral Movement Using DCOM and DLL Hijacking

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Local & remote Windows DLL Proxying

xll windows reverse shell

CVE-2026-28289

A fully featured Windows backdoor that uses email as a C&C server

C&C Botnet written in Python with fabric

Ping Exfiltration Command and Control (PiX-C2)

CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

Microsoft-Outlook-Remote-Code-Execution-Vulnerability


Proofpoint Email Gateway: Low level authenticated user to admin RCE

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Write-up for another forgotten Windows vulnerability (0day): Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape,…