
Log4ShellAuditor
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab


Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…

Burp Plugin to Bypass WAFs through the insertion of Junk Data

This script automates SQL injection testing using SQLMap with AI-powered decision making.

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

A cheat sheet that contains advanced queries for SQL Injection of all types.

woodpecker-plugins

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques


burp伪造ip爆破脚本

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)
