

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

POC for CVE-2024-34102 : Unauthenticated Magento XXE and bypassing WAF , You will get http connection on ur webhook

A new way to exploit CVE-2025-58360 bypass WAF

Exploit Path Traversal in esm-dev

Tools for auditing WAFS



CVE-2025-55182-bypass-waf

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.


PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1
