Skip to content
View cxzero's full-sized avatar
☺️
☺️

Block or report cxzero

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

Go 373 76 Updated Dec 16, 2025

Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation

JavaScript 67 21 Updated Dec 11, 2025

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Python 2,292 242 Updated Dec 7, 2025
C++ 207 58 Updated Jan 23, 2023

Explanation and full RCE PoC for CVE-2025-55182

Python 1,274 183 Updated Dec 8, 2025

Step-by-step walkthrough of CVE-2025-55182 (React2Shell) by tracing React's Flight protocol internals.

32 Updated Dec 10, 2025

Original Proof-of-Concepts for React2Shell CVE-2025-55182

JavaScript 948 105 Updated Dec 5, 2025

WIP open-source, cross-platform, and feature rich iOS/tvOS sideloading application. Supporting macOS, Linux, and Windows.

Rust 566 28 Updated Dec 21, 2025
Python 12 3 Updated Oct 31, 2025
Java 4 Updated Dec 26, 2024

Differential testing framework for HTTP implementations

Python 916 82 Updated Dec 9, 2025
Kotlin 11 1 Updated May 25, 2023

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

Java 6 2 Updated Jan 12, 2021

Examples for using the Montoya API with Burp Suite

Java 169 20 Updated Dec 1, 2025

A standalone Java Decompiler GUI

Java 14,931 2,469 Updated Jul 8, 2024

RootHideManagerApp

Objective-C 65 38 Updated Dec 5, 2025

iOS runtime dylib injection tool

Objective-C 254 46 Updated Jan 8, 2024

Browser-based redaction utility that lets you paste any payload—HTTP exchanges, JSON, YAML, CSV, configs—and instantly strip out sensitive values while preserving structure.

JavaScript 5 Updated Nov 20, 2025

Next Generation SSLKillSwitch with much more support!

Objective-C 681 91 Updated Mar 12, 2024

A GPT-empowered penetration testing tool

Python 9,979 1,463 Updated Dec 16, 2025

Cybersecurity AI (CAI), the framework for AI Security

Python 6,438 877 Updated Dec 19, 2025

Audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks.

PowerShell 129 10 Updated Aug 19, 2025

A local privilege escalation exploit for Splashtop Streamer for Windows prior to version 3.5.0.0

C++ 4 2 Updated Nov 22, 2023

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Go 1,708 130 Updated May 22, 2024

A collection of tips & tricks on how to escape a kiosk mode environment

30 1 Updated Nov 12, 2025

The new bridge between Burp Suite and Frida!

Java 1,826 225 Updated Oct 30, 2025

iOS 8.0-9.3.6 Jailbreak for 32-bit Devices

C 101 8 Updated Dec 13, 2025

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Python 5,518 840 Updated Apr 15, 2025
Python 814 100 Updated Sep 9, 2022

Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)

Python 6 Updated May 30, 2025
Next