
isr-sqlget
ISR-sqlget It's a blind SQL injection tool developed in Perl.

ISR-sqlget It's a blind SQL injection tool developed in Perl.

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

PHP Webshell with handy features

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Detection Script for MongoBleed Exploitation

wpsqli full SQLi extractor + dumper for CVE-2026-60137

chusa - 注射 - the new generation of sqlmap

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

Proof-of-concept exploit client for InfluxDB authentication bypass (CVE-2019-20933). Executes arbitrary queries against vulnerable InfluxDB instances…

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information