
CVE-2018-8062
Persistent XSS on Comtrend AR-5387un router

Persistent XSS on Comtrend AR-5387un router

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Steam Client Service Local Privilege Escalation Vulnerability

CVE-2021-34646 PoC

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

Detection method for Exim vulnerability CVE-2024-39929

Repository for CVE-2023-4549 vulnerability.

Proof-of-concept exploit for CVE-2023-23397, an Outlook/Exchange privilege escalation vulnerability that triggers NTLM credential theft via a…

Exploit for CVE-2026-18963, a critical unauthenticated account takeover in Keycloak's reset-credentials flow, chaining two bugs to bypass email…

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

Tool to find SMTP servers vulnerable to open relay

CVE-2026-28289

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.