
tcpdump
the TCPdump network dissector

the TCPdump network dissector

Proof-of-concept exploit and lab for CVE-2026-84753, an unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 via the mint-form-submit REST…

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…

Simulated Python demonstration of CVE-2026-8080 DKIM verification bypass, showing how non-compliant header canonicalization lets attackers inject…

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

A better whois and domain intelligence toolkit

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…

Insecure attachment handling when using Canary Mail or Blue mail

This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients…

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

Docker-based environment to reproduce CVE-2020-7247 (OpenSMTPD) with a Python exploit script for arbitrary command execution and reverse shell via…

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

POC to test CVE-2024-39929 against EXIM mail servers

Exploit script for WordPress Plugin Mail Masta 1.0 - CVE-2016-10956

Roundcube 1.0.0 <= 1.2.2 Remote Code Execution exploit and vulnerable container

Unauthenticated remote code execution exploit for Zimbra Collaboration Suite (CVE-2022-27925). Delivers a reverse shell payload to compromise…

nginx 1.15.10 patch against cve-2021-23017 (ingress version)

Proof-of-concept exploit for CVE-2021-33766 (ProxyToken) authentication bypass in Microsoft Exchange Server. Supports single and batch target…