
THM---Solar-exploiting-Log-4j
This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

CVE-2025-55182复现环境及RCE回显poc

Next.js RSC RCE Exploit Tool (CVE-2025-55182)