
CVE-2025-14847
This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.


An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…


This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Automated NoSQL database enumeration and web application exploitation tool.

PHP Webshell with handy features

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

The NoSQL Honeypot Framework

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

Salesforce object access auditor

Detection Script for MongoBleed Exploitation