


Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Exploit for CVE-2024-4577 PHP-CGI RCE on Windows, with WAF bypass and SSRF support. Provides multiple exploit variants for default, WAF, and SSRF…

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

Multi-mode vulnerability scanner for Next.js RCE (CVE-2025-66478/55182) with safe side-channel detection, RCE proof-of-concept, WAF bypass…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

CVE-2021-44228

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI LDAP/RMI injection, payload compilation, and WAF bypass techniques for testing…

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

CVE-2025-55182复现环境及RCE回显poc

CVE-2024-3640绕过Waf进行漏洞利用

A evolved version of assetnote CVE-2025-55182 scanner

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection, LDAP reference server, and WAF bypass techniques for testing Log4j RCE…