
CVE-2025-25101
WordPress Munk Sites plugin <= 1.0.7 - CSRF to Arbitrary Plugin Installation vulnerability

WordPress Munk Sites plugin <= 1.0.7 - CSRF to Arbitrary Plugin Installation vulnerability

The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing…

Cross Site Scripting Vulnerability in Flatpress CMS

Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)

Proof-of-concept exploit for CVE-2022-25257: CSRF parameter injection in SAS Logon 9.4 enabling warning-message spoofing for phishing attacks.

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

CVE-2024-21413 Açığını Kullanarak Giriş Bilgilerini Alma

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

Proof-of-concept exploit for CVE-2022-48429, a stored cross-site scripting vulnerability in JetBrains YouTrack dashboards enabling low-privileged…

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

Demonstrates an IDN homograph attack in Chromium extensions to spoof URLs, aiding in deception attacks by coercing victims into granting permissions…

This repository shows u some information on this vulnerability, which were found by me.

Windows active user credential phishing tool

Advanced Phishing tool

A Proof of Concept for the CVE-2021-46398 flaw exploitation