
CVE-2025-14847
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…


CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)

针对ESAPI 的ESAPI.encoder().encodeForSQL()方法,OracleCodec对象的sql 时间盲注利用

CVE-2026-54596 - Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

Datart v1.0.0-rc.3 JDBC Connection String Injection Leading to Arbitrary File Read

WordPress WP-Advanced-Search <= 3.3.9 - Unauthenticated SQL Injection

jeecg-boot unauthorized SQL Injection Vulnerability (CVE-2023-1454)

chusa - 注射 - the new generation of sqlmap

CVE-2025-14847 (MongoBleed)

POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method

SQL Injection vulnerability in NASA EOSDIS MODAPS due to improper input validation in the `category` parameter. This flaw allows attackers to…

Ghost CMS Content API Blind SQL Injection

CVE-2021-42670 - SQL Injection vulnerability in the Engineers online portal system.

SQL injection exploit for CVE-2025-26794 in Exim 4.98. Automated data extraction via time-based blind SQLi. For authorized penetration testing only.

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'