
CVE-2025-46817
Proof-of-concept for Redis Lua unpack integer overflow (CVE-2025-46817) demonstrating stack blow-up and potential RCE on Redis 8.2.1.

Proof-of-concept for Redis Lua unpack integer overflow (CVE-2025-46817) demonstrating stack blow-up and potential RCE on Redis 8.2.1.

[CVE-2016-2386] SAP NetWeaver AS JAVA UDDI Component SQL Injection

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)

golang test tool for mongobleed (cve-2025-14847)

Modern Events Calendar Lite <= 7.33.0 — Unauthenticated SQL Injection

CVE-2019-10708 SQL injection PoC

Python program to dump all the databases, exploiting NagiosXI sqli vulnerability

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

PoC of "DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste"

Automated Oracle CVE-2014-6577 exploitation via SQLi

Artica Proxy before 4.30.000000 Community Edition allows SQL Injection.

A tool to crash MySQL servers with CVE-2017-3599

CVE-2020-9483 OR CVE-2020-13921

A low-privileged user can exploit this via a crafted order_by parameter, causing time-based blind SQL injection.

Module for PrestaShop 1.6.1.X/1.7.X to fix CVE-2022-31181 / CVE-2022-36408 vulnerability (Chain SQL Injection)

version between CVE-2018-20433 and CVE-2019-5427