
burp-vps-proxy
This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).



A new way to exploit CVE-2025-58360 bypass WAF

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

CVE-2025-55182-bypass-waf


🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.


Tests your WAF with +160 payloads

POC for CVE-2024-34102 : Unauthenticated Magento XXE and bypassing WAF , You will get http connection on ur webhook


Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.