
Log4ShellAuditor
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

This script automates SQL injection testing using SQLMap with AI-powered decision making.

woodpecker-plugins

burp伪造ip爆破脚本

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

CVE-2024-3640绕过Waf进行漏洞利用

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

Stuff that doesn't deserves its own repository.

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

CVE-2025-25369

React2Shell (CVE-2025-55182) proof-of-concept (PoC) exploit demonstrating a CRITICAL remote code execution (RCE) vulnerability in modern web…