
CVE-2024-34693
CVE-2024-34693: Server Arbitrary File Read in Apache Superset

CVE-2024-34693: Server Arbitrary File Read in Apache Superset

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

CVE-2026-1337 - Neo4j - Log Injection

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

Deployed patch for CVE-2026-03200, a critical SQL injection vulnerability in Progress MOVEit, with validation and deployment details.

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection


Toolkit for CVE-2025-55182, also known as React2Shell.

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…

Proof-of-concept exploit for CVE-2026-72898, targeting Toucan2 behavior with malformed map options to reproduce the vulnerability and validate…

CVE-2021-40353 openSIS 8.0 SQL Injection Vulnerability

Proof-of-concept exploit for CVE-2022-31626, a buffer overflow in PHP's pdo_mysql with mysqlnd driver that can lead to remote code execution.

is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)

PoC exploit for CVE-2021-22146 that dumps Elastic ECE databases (versions 7.10.0 to 7.13.3) during internal penetration tests.

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…