
redis_exploit
CVE-2025-49844 (RediShell)

CVE-2025-49844 (RediShell)

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

Functional proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a pre-authentication heap memory disclosure vulnerability in MongoDB. Includes…

Sequelize JSON Cast SQL Injection

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC

Proof-of-concept exploit for CVE-2024-55656, an integer overflow in RedisBloom leading to heap-based OOB read/write and remote code execution in…

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

CVE-2025-60357- NoSQL(MongoDB) Injection POC

Go proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a MongoDB memory disclosure vulnerability. Crafts malformed BSON documents to leak…

CVE-2025-14847 MongoDB Memory Leak Exploit

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

PoC for CVE-2026-2005