
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Like curl, but it gets past Anubis and Cloudflare bot-walls.

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

CVE-2025-55182复现环境及RCE回显poc

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)


Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…


CVE-2025-29927 Proof of Concept

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478
