
SharpExchange
C# Tool to interact with MS Exchange based on MS docs

C# Tool to interact with MS Exchange based on MS docs

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Spoof file icons and extensions in Windows

Xss injection, WonderCMS 3.2.0 -3.4.2

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Chamilo-LMS (v2.0) CVE-2025-26153

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

A fork of the great TokenTactics with support for CAE and token endpoint v2

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…