
NextRce
React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

From Dork to Download: Automating Google Dorks with Playwright

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Tool to bypass 40X response codes.

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

woodpecker-plugins

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and…