
CVE-2026-26980
Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

Automatic SQL injection and database takeover tool

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

🔥 A powerful MongoDB auditing and pentesting tool 🔥


Blind SQL Injection Tool with Golang

Windows Oracle Database Attack Toolkit

A python library to automate time-based blind SQL injection

ISR-sqlget It's a blind SQL injection tool developed in Perl.


Scripts that can be used to exploit CVE-2019-15972 which was an Authenticated SQLi issue in Cisco Unified Call Manager (UCM).

PoC of SQL Injection vul(CVE-2020-9483,Apache SkyWalking)

CVE-2026-1337 - Neo4j - Log Injection


CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

redis未授权、redis_CVE-2022-0543检测利用二合一脚本