
postgres-bruteforcer
This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.


This repo contains my python script version of CVE-2025-14847 (MongoBleed)

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

PoC of SQL Injection vul(CVE-2020-9483,Apache SkyWalking)

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

CVE-2025-14847 (MongoBleed)

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc