
bbscope
Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0, 8.8.1

CVE-2025-49844 (RediShell)

Offensive MSSQL toolkit written in Python, based off SQLRecon

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

CVE-2021-27928 MariaDB/MySQL-'wsrep provider' 命令注入漏洞

Strafer: A tool to detect potential infections in Elasticsearch instances

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

Python tool for exploiting CVE-2021-35616

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

Proof-of-concept and detailed writeup for CVE-2026-51992, an SQL injection vulnerability in ClickHouse PostgreSQL dictionaries allowing arbitrary…


CVE-2026-1337 - Neo4j - Log Injection