
CVE-2025-1015
an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

JShell - Get a JavaScript shell with XSS.

Embed and hide any file in an HTML file

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)


PoC for CVE-2025-22131

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.