
CVE-2023-40869
Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.


CVE-2018-25031 tests

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Generate Payloads and Control Remote Machines. [Discontinued]

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…


CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

A Windows Remote Administration Tool in Visual Basic with UNC paths

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Use a Fake image.jpg to exploit targets (hide known file extensions)

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

ntlm relay attack to Exchange Web Services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

A simple script to generate a hidden url for social engineering.

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page