
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

Simulate data corruption attacks against multiple database systems (MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, Hadoop HDFS) with…

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

Exploit for CVE-2020-11579, an unauthenticated arbitrary file disclosure in PHPKB via a rogue MySQL server, allowing remote file exfiltration with…

Proof-of-concept exploit for CVE-2024-34693: authenticated arbitrary file read in Apache Superset via rogue MySQL server and LOAD DATA LOCAL INFILE…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Rogue MySQL server that captures and reads arbitrary files from connecting MySQL clients; ideal for red-team engagements and penetration testing to…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

Exploit POC for FOGProject authentication bypass (CVE-2025-58443) enabling full MySQL database dump, SSRF exploitation, and server file listing.

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…