
py-log4shellscanner
Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

PoC for CVE-2017-5487 - WordPress User Enumeration via REST

PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX


A cheat sheet that contains advanced queries for SQL Injection of all types.

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

Exploit for CVE-2025-55182 & CVE-2025-66478

React2Shell: An exploitation framework for CVE-2025-55182 (Next.js/React RCE).

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

Proof-of-concept research tool for CVE-2025-55182, a critical unauthenticated RCE in Next.js App Router caused by server-side object injection in…

Basic Proof of Concept (Poc) Exploit for React RSC - CVE-2025-55182

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

Nmap NSE script for scanning React2Shell (CVE-2025-55182)

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…
