
SPY-MASKER
It is a simple Python Script to hide phishing URL under a normal looking URL (google.com or facebook.com). It can be integrated into Phishing tools…

It is a simple Python Script to hide phishing URL under a normal looking URL (google.com or facebook.com). It can be integrated into Phishing tools…

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Contains evilginx phislets, gophish templates, burp suite extensions etc.

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

Web traffic interception simulation tool for cybersecurity research and defensive learning in isolated lab environments.

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Stored XSS exploit for Roundcube Webmail ≤1.6.6 (CVE-2024-42009) with zero-click email exfiltration via CSS animation event handlers. Includes SMTP…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Proof-of-concept exploit generator for reflected XSS in STIG Manager OIDC authentication, enabling session token theft via crafted callback URLs and…

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause,…

Chamilo-LMS (v2.0) CVE-2025-26153

Swagger UI (CVE-2018-25031) POC, [HTMLi, XSS].

CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

PoC of the phishing through setting browser in the fullscreen mode