
CVE-2025-8723
Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2024-3640绕过Waf进行漏洞利用

CVE-2025-55182 (React2Shell) Scanner

Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing.

A evolved version of assetnote CVE-2025-55182 scanner

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…

Next.js CVE-2025-29927 Vulnerability Scanner

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

New nuclei CVE

CVE-2025-55182 Auto Scanner - Improved Version For authorized CTF/testing purposes only

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

React2Shell (CVE-2025-55182) proof-of-concept (PoC) exploit demonstrating a CRITICAL remote code execution (RCE) vulnerability in modern web…

Nextjs RCE Exploit

CVE-2025-6389

Basic Proof of Concept (Poc) Exploit for React RSC - CVE-2025-55182

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)