
CVE-2023-48084-Revised
Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

wpsqli full SQLi extractor + dumper for CVE-2026-60137

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

A new open-source tool to quickly audit SAP permissions.

The easiest, and most secure way to access and protect all of your infrastructure.

POCs to demonstrate CVE-2026-42167 in ProFTPD

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

ISR-sqlget It's a blind SQL injection tool developed in Perl.

chusa - 注射 - the new generation of sqlmap

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

CVE-2019-14900

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Python tool for exploiting CVE-2021-35616