
Advanced-SQL-Injection-Cheatsheet
A cheat sheet that contains advanced queries for SQL Injection of all types.

A cheat sheet that contains advanced queries for SQL Injection of all types.


High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Burp Plugin to Bypass WAFs through the insertion of Junk Data

🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

CVE-2025-55182 POC

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

WebPwn3r - Web Applications Security Scanner.

Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…


Remote Code Injection In Log4j


A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Exploit for CVE-2025-55182 & CVE-2025-66478