
phpMyAdmin-CVE-2020-5504-Exploit
Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

Open-source vulnerability database aggregating CVE data from multiple sources with a web UI and API. Maps vulnerabilities to specific software…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

CVE-2026-44680 exploit framework for MikroORM SQL injection. Detects and exploits JSON path injection vulnerabilities with UNION-based and blind data…

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

An modular asset discovery framework written in python to automate the repeating manual work

Exploit for CVE-2025-5878 targeting ESAPI's encodeForSQL() method with OracleCodec, enabling time-based blind SQL injection. Supports database…

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

SQL Injection vulnerability in NASA EOSDIS MODAPS due to improper input validation in the `category` parameter. This flaw allows attackers to…

Proof-of-concept exploit for CVE-2023-31714, a pre-authentication SQL injection in Chitor-CMS < 1.1.2. Automates database enumeration and credential…

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Blind SQL injection exploit for ZoneMinder (CVE-2024-51482) with time-based extraction, database enumeration, and credential dumping capabilities.

Automated NoSQL database enumeration and web application exploitation tool.

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

Proof-of-concept exploit for CVE-2025-2011, a SQL injection vulnerability in WordPress Depicter Plugin 3.6.1, enabling database enumeration and data…