
CVE-2026-42031-SQL-Injection-Scanner
Automated SQL injection scanner for CKAN DataStore, detecting and validating CVE-2026-42031 with multi-target scanning, data dumping, and report…

Automated SQL injection scanner for CKAN DataStore, detecting and validating CVE-2026-42031 with multi-target scanning, data dumping, and report…

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

Proof-of-concept exploit for CVE-2021-2175, an Oracle Database Vault metadata exposure vulnerability, demonstrating unauthorized access to sensitive…

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

wpsqli full SQLi extractor + dumper for CVE-2026-60137

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

Code Generator Pro <= 1.2 - Unauthenticated SQL Injection

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Fancy Product Designer <= 6.4.3 - Unauthenticated SQL Injection

Checks for exposed Redis servers

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting


mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…