
spring4shell-scan
A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

A program for testing WAF functionality

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.