
CVE-2026-33980
KQL Injection in adx-mcp-server via table_name parameter — CVSS 8.8

KQL Injection in adx-mcp-server via table_name parameter — CVSS 8.8

Cypher Injection in graphiti-core (getzep/graphiti) via unsanitized node_labels — CVSS 8.1

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

Proof-of-concept and detailed writeup for CVE-2026-51992, an SQL injection vulnerability in ClickHouse PostgreSQL dictionaries allowing arbitrary…

Django StringAgg SQL Injection (CVE-2020-7471)

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

Sequelize JSON Cast SQL Injection

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection

CVE-2019-14900

web2py/web2py @ e94946d

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods…

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization…

SQL Injection vulnerability discovered in Grocery Store Management System 1.0

Proof-of-concept exploit for CVE-2025-59470, a command injection vulnerability in PostgreSQL's pg_backup extension, allowing authenticated backup…