

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

POC BLH Magelang CSIRT 2026 by babyrootkid


Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess



290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

Cisco Email Security Appliance: Local Privilege Escalation and Shell Escape

Cisco Email Security Appliance: Remote Code Execution - RCE from config file

Proofpoint Email Gateway: Unauthenticated RCE

Proofpoint Email Gateway: Low level authenticated user to admin RCE