
commix
Automated All-in-One OS Command Injection Exploitation Tool

Automated All-in-One OS Command Injection Exploitation Tool

Undetected version of the Playwright testing and automation library.


Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

CVE-2025-61638 PoC

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

xpath is a fast, multi-technique XPath injection scanner written in Nim. It focuses on practical detection, response comparison, visible extraction,…

Like curl, but it gets past Anubis and Cloudflare bot-walls.


Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications