
CVE-2026-72898
Python exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password reset endpoint that creates admin accounts and extracts…

Python exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password reset endpoint that creates admin accounts and extracts…

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers



MYSQL UDF Exploit

Python SQL injection framework

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

CVE-2021-27928-POC

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

PostgreSQL Remote Code Executuon

jackson unserialize

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…