
CVE-2026-24031
Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Exploits chained WordPress REST API SQL injection to enumerate databases and dump tables, with UNION-based, parallel boolean-blind, and time-based…

Python decryption tool for SSCMS CMS encrypted database configurations and user passwords using a hardcoded DES key and IV.

Exploit tool for Redis 4.x/5.x that achieves remote code execution by loading a custom RedisModule (exp.so) through a rogue server, enabling…

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

A new open-source tool to quickly audit SAP permissions.

The easiest, and most secure way to access and protect all of your infrastructure.

Security assessment and post-exploitation toolkit for Microsoft SQL Server with enumeration, privilege escalation, code execution, lateral movement,…

Exploit framework for Discuz! X5.0 authentication bypass (CVE-2026-49952) enabling unauthenticated database backup access via UC_KEY token reuse.…

Proof-of-concept exploits for CVE-2026-42167, a SQL injection vulnerability in ProFTPD's mod_sql logging pipeline enabling unauthenticated SQL…

Exploit for CVE-2025-29705 targeting a code generation tool with missing access controls, enabling unauthorized database credential disclosure across…

Forensic tool to extract and analyze SQLite databases from rooted Android devices, generating structured XML reports for digital investigations.

Blind SQL injection tool for automated database schema enumeration and data extraction. Supports 20+ database engines with evasion techniques for WAF…

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

Java ORM library implementing JPA specification for object-relational mapping, with database abstraction and query capabilities for enterprise…

CVE-2026-23479 Redis Use-After-Free vulnerability detection tool