
MSSqlPwner
Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

🔥 A powerful MongoDB auditing and pentesting tool 🔥

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

CVE-2025-29927: Next.js Middleware Exploit

Proof-of-concept for SQL injection authentication bypass in Simple Content Management System PHP, allowing unauthenticated attackers to gain admin…

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Unauthenticated SQL injection exploit for ABO.CMS 5.8 enabling login bypass and database takeover via the tb_login parameter.

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

Chatwoot SQL injection in FilterService

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…