
TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2

A fork of the great TokenTactics with support for CAE and token endpoint v2

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Python exploit for CVE-2026-32201, a reflected XSS in Microsoft SharePoint Server, enabling unauthenticated spoofing and data modification via…

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

evilginx3 + gophish

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Stored XSS via CSRF in Beetel 777VR1 Router

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

Repository for CVE-2023-4549 vulnerability.

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

Azure JWT Token Manipulation Toolset

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.