
CVE-2026-30081
Documentation of CVE-2026-30081, a high-severity cleartext transmission vulnerability in Quantum Networks QN-I-470 router firmware 6.1.1.B1, allowing…

Documentation of CVE-2026-30081, a high-severity cleartext transmission vulnerability in Quantum Networks QN-I-470 router firmware 6.1.1.B1, allowing…

This is a fast, asynchronous Python tool that fingerprints domains for likely Next.js App Router / React Server Components (RSC) infrastructure. (I…

CSRF vulnerability in FD602GW-DX-R410 router allows remote attackers to reboot the device via a crafted POST request to /boaform/admin/formReboot…

Proof-of-concept for authenticated stored cross-site scripting (XSS) vulnerability in Multilaser RE 170 router firmware 2.2.6733, with reproduction…

D-Link DIR-845L router is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.

Learn how I found my first two CVEs by pure accident.

A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

CVE-2025-26202

A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications.

Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing

Proof-of-concept for stored cross-site scripting (XSS) vulnerability in D-Link DSL-2730E routers via the username parameter on the maintenance…