
CVE-2026-3494_Verfication
Reproduces and analyzes CVE-2026-3494, an audit logging bypass in MariaDB server_audit plugin, using Docker-based multi-version testing to compare…

Reproduces and analyzes CVE-2026-3494, an audit logging bypass in MariaDB server_audit plugin, using Docker-based multi-version testing to compare…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

A collection of web pages vulnerable to SQL injection flaws

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.

SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection

genesisQL-sqli-CVE-2026-36826

Proof-of-concept for CVE-2025-69214: SQL injection in OpenSTAManager's ajax_select.php componenti endpoint. Includes vulnerable code analysis,…

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

Reproducible Docker lab for CVE-2025-25257, demonstrating SQL injection bypass and data exfiltration via HTTP Authorization header on a simulated…

Proof-of-concept exploit for CVE-2025-14847, a MongoDB bleed vulnerability. Enables verification of vulnerable instances and understanding of attack…