
CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration
Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

C# Tool to interact with MS Exchange based on MS docs

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Phishing with a fake reCAPTCHA

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Scripts to clone CA certificates for use in HTTPS client attacks.

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

A Windows Remote Administration Tool in Visual Basic with UNC paths

Read more at Medium

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.