
WEAPONIZING-CVE-2024-4367
CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

An automated Wireless RogueAP MITM attack framework.

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

CVE-2019-13498

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…

Hunt down social media accounts by username across social networks

Redirect All Traffic Through Tor Network For Kali Linux

Proof-of-concept exploit for stored XSS vulnerability in VanillaForum 2.6.3, demonstrating arbitrary HTML/script injection via insufficient input…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Educational Android (Termux) toolkit for learning penetration testing, OSINT, social engineering, and network security through hands-on scripts,…

cve-2019-11510, cve-2019-19781, cve-2020-5902, cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084,…

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.