
MailAccess
Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

Data leak checker & OSINT Tool

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

Scans DNS MX records to detect misconfigured, expiring, or unregistered domains vulnerable to email takeover, with automatic reclamation support for…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

OSINT Tool for Finding Passwords of Compromised Email Addresses

Automated pentesting report generator with vulnerability database, severity classification, and client information gathering via subdomain and email…

Template Injection in Email Templates leads to code execution on Jira Service Management Server

A collection of python apps and shell scripts to email an xlsx spreadsheet of new vulnerabilities in the NIST CVE database and their associated…

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)

This tools will extracts and dumps Email + SMTP from vBulletin database server

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior…

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)