
Phishious
An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP email delivery, malicious RTF attachment generation, and optional…

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

Creates professional phishing emails with 20+ templates for credential harvesting, including HTML generation and direct email delivery to targets.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

Super organized and flexible script for sending phishing campaigns

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Postfix SMTP Smuggling - Expect Script POC

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough