
CVE-2025-61638
Proof-of-concept exploit for CVE-2025-61638, a stored XSS vulnerability in MediaWiki's Sanitizer::validateAttributes. Tests for the flaw across…

Proof-of-concept exploit for CVE-2025-61638, a stored XSS vulnerability in MediaWiki's Sanitizer::validateAttributes. Tests for the flaw across…

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

Multi-technique vulnerability detector for CVE-2025-55182 in React/Next.js applications. Tests gadget chains, RCE payloads, and WAF bypass variants…

Docker-based security lab demonstrating Apache Struts2 S2-045 (CVE-2017-5638) exploitation and defense, featuring vulnerable and patched applications…

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Generic Scanner for Apache log4j RCE CVE-2021-44228

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

StoreKeeper for WooCommerce <= 14.4.4 - Unauthenticated Arbitrary File Upload

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Enhance your malware detection with WAF + YARA (WAFARAY)

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…