
commix
Automated Αll-in-One OS command injection exploitation tool.

Automated Αll-in-One OS command injection exploitation tool.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Nextjs RCE Exploit

next.js rce exploit

Detect and bypass web application firewalls and protection systems


HackBar plugin for Burpsuite

Tools for auditing WAFS

The most powerful CRLF injection (HTTP Response Splitting) scanner.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。


Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.