
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

The most powerful CRLF injection (HTTP Response Splitting) scanner.

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

From Dork to Download: Automating Google Dorks with Playwright

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

CVE-2025-55182复现环境及RCE回显poc

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

A evolved version of assetnote CVE-2025-55182 scanner

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Multi-technique vulnerability detector for CVE-2025-55182 in React/Next.js applications. Tests gadget chains, RCE payloads, and WAF bypass variants…