
commix
Automated Αll-in-One OS command injection exploitation tool.

Automated Αll-in-One OS command injection exploitation tool.

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

Local file inclusion exploitation tool

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

Automated exploit tool for CVE-2025-55182 in Next.js React Server Components. Enables remote command execution with built-in WAF bypass, custom…

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Automatic SQL injection and database takeover tool

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

Reproduces CVE-2025-29927 middleware authorization bypass in Next.js 14.2.24 and demonstrates exploitation with curl to bypass authentication and…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具