
CVE-2025-55182
Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Local file inclusion exploitation tool

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

StoreKeeper for WooCommerce <= 14.4.4 - Unauthenticated Arbitrary File Upload

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

From Dork to Download: Automating Google Dorks with Playwright

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)