
Storm-Breaker
Social engineering tool [Access Webcam & Microphone & Location Finder] With {Py,JS,PHP}

Social engineering tool [Access Webcam & Microphone & Location Finder] With {Py,JS,PHP}

CVE-2019-13498

This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung…

Python Script for Email Bombing which supports Gmail, Yahoo, Hotmail/Outlook

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Persistent XSS on Comtrend AR-5387un router

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Cross Site Scripting on sanitization-management-system

XLL Phishing Tradecraft

ntlm relay attack to Exchange Web Services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

POC CVE-2025-26318

Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…

cve-2024-21413

Proof-of-concept exploit for a cross-site scripting (XSS) vulnerability in Microsoft Outlook for iOS, enabling email-based spoofing attacks and…