
atproto
Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

Working POC of CVE-2026-6664 written by Sonnet 4.6

Offensive MSSQL toolkit written in Python, based off SQLRecon

CVE-2026-25514 - FacturaScripts has SQL Injection in Autocomplete Actions

CVE-2026-24417 - OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

Proof-of-concept repository for CVE-2025-69213, demonstrating a SQL injection vulnerability in OpenSTAManager's ajax_complete.php endpoint with…

CVE-2025-69215 - OpenSTAManager has an SQL Injection in the Stampe Module