


Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…

Burp Plugin to Bypass WAFs through the insertion of Junk Data

A cheat sheet that contains advanced queries for SQL Injection of all types.



This is the data that powers the PortSwigger URL validation bypass cheat sheet.


Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.

Exploit for CVE-2021-45468, an Imperva WAF bypass.


Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…