
react2shell-scanner
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Multi-mode vulnerability scanner for CVE-2025-66478 (Next.js RSC RCE) with WAF bypass, interactive shell, batch scanning, and JSON automation output…

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Automated XSS scanner with vulnerability confirmation, WAF bypass via encoded payloads, and cookie extraction for penetration testing of web…

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Automated PHP-CGI parameter injection exploit tool targeting CVE-2024-4577 and CVE-2024-8926. Supports command execution, file upload/download, WAF…

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating JNDI injection-based remote code execution against vulnerable Log4j versions,…

Scanner for CVE-2025-55182 RCE in Next.js/React apps. Detects vulnerability via multipart PoC, supports safe side-channel mode, WAF bypass, and…

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

Generic Scanner for Apache log4j RCE CVE-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) with curl-based vulnerability checks, LDAP/RMI payload generation, and WAF bypass techniques…

Graphical RCE exploit tool for CVE-2025-55182 in Next.js RSC. Supports remote command execution, arbitrary JS execution, file read/write, directory…

Exploit tool for CVE-2024-3640 that bypasses WAF using XML comment injection to achieve command execution and custom memory shell deployment.