
React2Shell-Scanner
Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Testing WAF protection against CVE-2021-44228 Log4Shell

A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Proof-of-concept exploit for CVE-2020-6519 - a Chromium zero-day that fully bypasses Content Security Policy (CSP) across platforms, enabling script…

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

StoreKeeper for WooCommerce <= 14.4.4 - Unauthenticated Arbitrary File Upload

[漏洞复现] 全球首款基于RSC特性能绕过WAF检测的CVE-2025-55182 React Server RCE 漏洞 EXP。

Demonstrates CVE-2022-31813 Apache HTTP Server bypass using X-Real-IP header manipulation to evade access controls, with a Docker-based test…

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Documented XSS exploit for ZKBio CVSecurity v.6.4.1 with WAF bypass, enabling privilege escalation from Template Editor to administrator via crafted…