
fileless-xec
Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Disrupt WAF by abusing SSL/TLS Ciphers

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Next-gen logical WAF engine built in SWI-Prolog. Features an inductive learning brain running at 2M+ LIPS with an integrated recursive decoder to…

CVE-2025-55182复现环境及RCE回显poc

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

A evolved version of assetnote CVE-2025-55182 scanner

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Nextjs RCE Exploit

New nuclei CVE

CVE-2025-55182 (React2Shell) Scanner

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)