
evilqr
Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

PoC of CVE-2020-16947 (Microsoft Outlook RCE vulnerablility)

PoC exploit code for CVE-2021-26855

A python server tool based on flask , this tool can phish some Facebook credentials!

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。


Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

CVE-2021-33766-poc

WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

POC BLH Magelang CSIRT 2026 by babyrootkid

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

PoC CVE-2023-51764

.json and .yaml files used to exploit CVE-2018-25031

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…
