
Leantime-POC
CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477
CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

CVE-2020-12625: Cross-Site Scripting via Malicious HTML Attachment in Roundcube Webmail

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

Unauthenticated SSRF + Open Email Relay in Chamilo LMS via install.ajax.php — CVSS 7.5

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

Windows active user credential phishing tool

Advanced Phishing tool

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

Real-time two-factor phishing tool that automates credential harvesting by intercepting credentials from a phishing site and submitting them to the…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks