
CVE-2026-33715
Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2
Cross-Site Scripting vulnerability in Advanced REST Client v.17.0.9 exploit

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

Hacking tools pack & backdoors generator.

CVE-2020-20093; 20094; 20095; 20096, 2022-28345 RTLO Injection URI Spoofing

Critical Flaws in Traccar GPS System Expose Users to Remote Attacks

XSS-to-RCE exploit for Wonder CMS 3.2.0–3.4.2 with automated payload delivery, reverse shell, and cookie theft via malicious theme installation.

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

Proof-of-concept exploit for stored XSS and insecure permissions in Collabora CODE <= 4.2.2 via the Vereign WOPI API, enabling account hijacking and…

Proof-of-concept for CVE-2020-16270, an XSS vulnerability in OLIMPOKS under 3.3.39, demonstrating remote injection of malicious JavaScript to steal…

Proof of concept for a blind/persistent XSS vulnerability in Blinger.io helpdesk, demonstrating remote code execution in admin panels via crafted…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…