


Reflected XSS vulnerability in MikroTik Hotspot login page

Proof-of-concept and technical writeup for CVE-2025-59382, an unauthenticated password reset URL injection in QNAP NAS that enables a…

This repository documents CVE-2026-48849, a Stored Cross-Site Scripting (XSS), HTML Injection, and CSS Injection vulnerability discovered in…


CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

Security awareness training tool for authorized phishing simulations and internal IT audits

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…


CVE-2026-30691: Stored Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer


Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…


CVE-2026-24415 - OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

CVE-2025-52204: Reflected XSS / HTML Injection in Znuny OTRS