
CVE-2026-52887-NocoBase-SQLi-RCE
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

Django StringAgg SQL Injection (CVE-2020-7471)


PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…


[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection

CVE-2019-14900

web2py/web2py @ e94946d

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods…

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization…

SQL Injection vulnerability discovered in Grocery Store Management System 1.0


CVE-2025-51458 - DB-GPT Pre-Auth SQL Injection PoC

Reproduction of SQL Injection Vulnerabilities in OpenHIS
