
CVE-2025-49844
Scanner and educational guide for CVE-2025-49844 (RediShell), a Redis Lua scripting use-after-free vulnerability. Checks Redis servers for exposure,…

Scanner and educational guide for CVE-2025-49844 (RediShell), a Redis Lua scripting use-after-free vulnerability. Checks Redis servers for exposure,…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

wpsqli full SQLi extractor + dumper for CVE-2026-60137

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

sscms database decrypt

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

druid_decode

OpenFire 管理后台账号密码解密

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

A new open-source tool to quickly audit SAP permissions.

The easiest, and most secure way to access and protect all of your infrastructure.

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

POCs to demonstrate CVE-2026-42167 in ProFTPD