
commix
Automated All-in-One OS Command Injection Exploitation Tool

Automated All-in-One OS Command Injection Exploitation Tool

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Like curl, but it gets past Anubis and Cloudflare bot-walls.

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

Local file inclusion exploitation tool

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

CVE-2025-55182 - Tool React2Shell

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)