
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Disrupt WAF by abusing SSL/TLS Ciphers

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…


RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

[漏洞复现] 全球首款基于RSC特性能绕过WAF检测的CVE-2025-55182 React Server RCE 漏洞 EXP。

CVE-2025-55182 security test kit: CLI scanner + Chrome extension + Nuclei templates + Docker lab.

CVE-2025-55182复现环境及RCE回显poc

Header bypass for CVE-2025-55182 (React Server Components RCE).

React2Shell (CVE-2025-55182) Exploit