
CVE-2026-9082
Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

Exploit script for ServiceNow CVE-2024-4879 that enables unauthenticated remote code execution, with mass target scanning and database dumping…

Automatic SQL injection and database takeover tool

Pull Request-like Review/Approval flow for database queries. For compliant but smooth Engineering access to production.

An egress firewall for untrusted workloads.

The NoSQL Honeypot Framework

An modular asset discovery framework written in python to automate the repeating manual work

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

POCs to demonstrate CVE-2026-42167 in ProFTPD

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

CVE-2026-72898

Chatwoot SQL injection in FilterService

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…