
burp-awesome-tls
Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

Next generation web scanner

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

Multi-technique vulnerability detector for CVE-2025-55182 in React/Next.js applications. Tests gadget chains, RCE payloads, and WAF bypass variants…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

CVE-2021-44228 Log4j2 remote code injection exploit with JNDI payload generation, WAF bypass techniques, and practical exploitation walkthrough for…

A evolved version of assetnote CVE-2025-55182 scanner

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

From Dork to Download: Automating Google Dorks with Playwright

CVE-2025-6389

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…