
PoC-CVE-2025-66224
Proof-of-concept exploit for CVE-2025-66224 demonstrating remote code execution in OrangeHRM via command injection in the sendmail_path parameter,…

Proof-of-concept exploit for CVE-2025-66224 demonstrating remote code execution in OrangeHRM via command injection in the sendmail_path parameter,…

Authenticated SQL Injection Vulnerability in VTiger Open Source CRM v7.5

KQL Injection in adx-mcp-server via table_name parameter — CVSS 8.8

Proof-of-concept exploit for CVE-2025-24999, demonstrating privilege escalation in Microsoft SQL Server via the MS_DatabaseManager role.

CVE-2026-33917: SQL Injection Vulnerability in OpenEMR <8.0.0.3

Cypher Injection in graphiti-core (getzep/graphiti) via unsanitized node_labels — CVSS 8.1


Koha CVE-2025-22954: SQL Injection in lateissues-export.pl

SQL Injection vulnerability discovered in Grocery Store Management System 1.0

CVE-2025-14847 MongoDB Memory Leak Exploit

Artica Proxy before 4.30.000000 Community Edition allows SQL Injection.

CVE-2025-14847 explaination and lab

Proof-of-concept exploits for three vulnerabilities in Syncfusion file managers: directory traversal leading to arbitrary file read/write/delete, and…

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only

CVE-2023-21173 Exploit - Remote Code Execution in SQL Server 2022

version between CVE-2018-20433 and CVE-2019-5427