
nowafpls
Burp Plugin to Bypass WAFs through the insertion of Junk Data

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

WebPwn3r - Web Applications Security Scanner.

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

CVE-2021-40346 PoC (HAProxy HTTP Smuggling)

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

CVE-2025-55182 security test kit: CLI scanner + Chrome extension + Nuclei templates + Docker lab.

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

CVE-2025-55182 (React2Shell) Scanner

A evolved version of assetnote CVE-2025-55182 scanner

Nextjs RCE Exploit

New nuclei CVE

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)