
Next.js-RCE-CVE-2025-55182
next.js rce exploit

next.js rce exploit

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Next generation web scanner

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Hide your Powershell script in plain sight. Bypass all Powershell security features

Advanced reconnaissance utility

Tests your WAF with +160 payloads


A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

This script automates SQL injection testing using SQLMap with AI-powered decision making.

PyMultitor - Python Multi Threaded Tor Proxy

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.