
CVE-2023-49968
Customer Support System 1.0 - SQL Injection Vulnerability in manage_department.php via "id" URL Parameter

Customer Support System 1.0 - SQL Injection Vulnerability in manage_department.php via "id" URL Parameter

RSVPMarker <= 10.6.6 - Unauthenticated SQL Injection

Customer Support System 1.0 - SQL Injection Vulnerability in edit_customer via "id" URL Parameter

Docker-based lab demonstrating CVE-2019-9193 PostgreSQL arbitrary command execution via COPY FROM PROGRAM, with step-by-step PoC for security testing…

Mongo Vulnub Lab...Try to Hack IT.....!

CVE-2016-4999

SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

Reproduces and analyzes CVE-2026-3494, an audit logging bypass in MariaDB server_audit plugin, using Docker-based multi-version testing to compare…

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

django 漏洞:CVE-2020-7471 Potential SQL injection via StringAgg(delimiter) 的漏洞环境和 POC

h2-jdbc(https://github.com/h2database/h2database/issues/3195) & mysql-jdbc(CVE-2021-2471) SQLXML XXE vulnerability reproduction.

poc for CVE-2025-14847

Django QuerySet.annotate(), aggregate(), extra() SQL 注入

GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)

Security research project — SQL Injection vulnerability exploitation and mitigation

vulhub/H2-database/CVE-2022-23221

Proof-of-concept demonstrating CVE-2026-17351 SQL injection bypass in pgAdmin 4's AI Assistant via sqlparse/PostgreSQL lexer differential, including…

ZenoMinder Blind SQL Injection PoC