
CVE-2025-49132
Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…


wpsqli full SQLi extractor + dumper for CVE-2026-60137

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

Code Generator Pro <= 1.2 - Unauthenticated SQL Injection

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Fancy Product Designer <= 6.4.3 - Unauthenticated SQL Injection

Checks for exposed Redis servers

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting


mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描


SQL injection exploit for CVE-2025-26794 in Exim 4.98. Automated data extraction via time-based blind SQLi. For authorized penetration testing only.

CVE-2026-25746 - SQL Injection Vulnerability in OpenEMR <8.0.0


Security advisory for CVE-2026-30655: unauthenticated SQL injection in esiclivre (/reset/index.php).