
CVE-2025-55182
Chrome extension and Shodan scanner for detecting and demonstrating RCE vulnerabilities in React Server Components (RSC) and Next.js applications,…

Chrome extension and Shodan scanner for detecting and demonstrating RCE vulnerabilities in React Server Components (RSC) and Next.js applications,…

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.

ImaegMagick Code Execution (CVE-2016-3714)

POC exploit for CVE-2015-10141

A chromium extension exploitation toolkit

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

Burp extension scanner for CRLF injection and HTTP desync attacks, using mutated probes, WAF false-positive checks, and optional…

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE

Burp extension for wordpress security scanning

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046

Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.

Python exploit for RCE in Wordpress

Proof-of-concept exploit for CVE-2024-44902, a deserialization vulnerability in ThinkPHP v6.1.3–v8.0.4 enabling remote code execution via crafted…