
CVE-2025-55182-research
🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

CVE-2025-6389

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

A simple script just made for self use for bypassing 403

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Header bypass for CVE-2025-55182 (React Server Components RCE).

Exploit for CVE-2021-45468, an Imperva WAF bypass.

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

Burp Plugin to Bypass WAFs through the insertion of Junk Data