
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

This script automates SQL injection testing using SQLMap with AI-powered decision making.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A cheat sheet that contains advanced queries for SQL Injection of all types.


StoreKeeper for WooCommerce <= 14.4.4 - Unauthenticated Arbitrary File Upload

[漏洞复现] 全球首款基于RSC特性能绕过WAF检测的CVE-2025-55182 React Server RCE 漏洞 EXP。


XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

CVE-2025-25369

A new way to exploit CVE-2025-58360 bypass WAF

React2Shell (CVE-2025-55182) proof-of-concept (PoC) exploit demonstrating a CRITICAL remote code execution (RCE) vulnerability in modern web…


Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…
