
CVE-2026-1357-POC
Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

CVE-2025-55182 (React2Shell) Scanner

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

Disrupt WAF by abusing SSL/TLS Ciphers

Proof-of-concept for CVE-2024-34102 exploiting unauthenticated Magento XXE and WAF bypass by sending a crafted request to the…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Automated Αll-in-One OS command injection exploitation tool.

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Hide your Powershell script in plain sight. Bypass all Powershell security features

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

This script automates SQL injection testing using SQLMap with AI-powered decision making.

The most powerful CRLF injection (HTTP Response Splitting) scanner.