
CVE-2026-87902
Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Pre-auth RCE proof-of-concept chaining a WordPress REST batch API auth bypass with WP_Query SQL injection to dump hashes, add admin users, or plant a…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Local file inclusion exploitation tool

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

CVE-2025-55182 Auto Scanner - Improved Version For authorized CTF/testing purposes only

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

This script automates SQL injection testing using SQLMap with AI-powered decision making.

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)

A evolved version of assetnote CVE-2025-55182 scanner

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection, LDAP reference server, and WAF bypass techniques for testing Log4j RCE…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)