
NextRce
React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Automated CDN origin-IP discovery skill for Claude Code that runs 40+ prioritized OSINT methods, cross-validates candidates via SSL and HTTP…

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness and…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

From Dork to Download: Automating Google Dorks with Playwright

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Tool to bypass 40X response codes.

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

woodpecker-plugins

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…