
CVE-2025-24054
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

Embed and hide any file in an HTML file

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

Spoof file icons and extensions in Windows

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Use a Fake image.jpg to exploit targets (hide known file extensions)

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

PoC for CVE-2025-22131

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…