
chrome-vuln-scanner
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

Share Buttons – Social Media <= 1.0.2 - Unauthenticated SQL Injection

Scripts to clone CA certificates for use in HTTPS client attacks.

flash钓鱼源码 中文+英文

camjacking templates

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Proof-of-concept exploit for a reflected XSS vulnerability in the WordPress Sassy Social Share plugin via the heateor_mastodon_share parameter, with…

Ruby on Rails Phishing Framework

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout…

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…

Pastejacking - PasteZort

Tool Information Gathering & social engineering Write By [Python,JS,PHP]

Cryptographically secure messaging and social networking service.

Automated OSINT reconnaissance tool that queries Google and social platforms to gather intelligence on usernames and queries, with proxy rotation and…