
CVE-2026-33715
Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

Proof-of-concept exploit for a critical SQL injection vulnerability in WordPress Email Subscribers plugin. Includes exploitation details, HTTP…

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

PrestaShop AdminLogin Email Enumeration PoC - CVE-2025-51586. This repository provides an ethical Proof-of-Concept (PoC) for the PrestaShop…

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute…

OSINT tool to find breached emails, databases, pastes, and relevant information

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Simple tool for extracting emails from websites


OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Enumerate Microsoft 365 Groups in a tenant with their metadata

User Enumeration vulnerability in Kaiten (workflow management system)

Automated OSINT tool for phone number discovery, pattern detection, and cross-platform correlation.

CVE-2023-38035 Recon oriented exploit, extract company name contact information

CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1

Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more…