
CVE-2025-1306
Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

It is a simple Python Script to hide phishing URL under a normal looking URL (google.com or facebook.com). It can be integrated into Phishing tools…

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

An active cyber defense & honeypot system for OpenWrt routers running from a USB drive.

FragAttacks WiFi penetration framework — CVE-2020-24586/87/88

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Additional exploits for XSS in Cisco ASA devices discovered by PTSwarm


Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

USBCoercer turns an ESP32 development board with native USB-OTG into an Ethernet-over-USB gadget capable of coercing proxy configuration via WPAD.

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

This repository presents a proof-of-concept of CVE-2024-50677

【Teedy 1.11】Account Takeover via XSS

PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios…