
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)


Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Advanced reconnaissance utility

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

Remote Code Injection In Log4j

This script automates SQL injection testing using SQLMap with AI-powered decision making.

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…