
evilqr
Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Proof-of-concept exploit for a cross-site scripting (XSS) vulnerability in Microsoft Outlook for iOS, enabling email-based spoofing attacks and…

【Teedy 1.11】Account Takeover via XSS

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…