
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

PoC exploit for CVE-2026-32621 demonstrating Apollo Federation deepMerge prototype pollution via crafted GraphQL aliases, with patched-version tests.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Documentation and proof-of-concept for CVE-2026-42208, a critical pre-authentication SQL injection vulnerability in the LiteLLM AI gateway enabling…

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

ML-based detection of SQL injection and XSS attacks in API requests using TF-IDF vectorization and logistic regression classification.

High-performance, low-maintenance Nginx module acting as a DROP-by-default WAF, blocking XSS, SQL injection, and other web attacks using simple…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.