
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…


This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

CVE-2025-55182 (React2Shell) Scanner

a simple react2shell poc with basic waf bypass

A evolved version of assetnote CVE-2025-55182 scanner

CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

CVE-2025-55182 & CVE-2025-66478 proof of concepts

CVE-2025-55182 - Tool React2Shell


WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…