
PoC-CVE-2026-20841
Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

evilginx3 + gophish

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Hacking systems with the automation of PasteJacking attacks.

Proof of Concept (PoC) for CVE-2024-7014 (EvilVideo) Exploit

CVE-2019-13498

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

Academy LMS <= 5.10 CSRF

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

A tool to transform Chromium browsers into a C2 Implant

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.