
nmap
High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Demonstrates a critical GraphQL batching alias-confusion SQL injection (CVE-2026-5432) with a vulnerable Node.js server and Python exploit for…

PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production


PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…