
CVE-2026-69083_exploit
Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

Rogue-MySql-Server

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

PoC exploit for CVE-2021-22146 that dumps Elastic ECE databases (versions 7.10.0 to 7.13.3) during internal penetration tests.

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)

Proof-of-concept exploit for CVE-2026-54596: authenticated SQL injection in ITFlow's recurring_invoice_frequency parameter enabling full database…

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

CVE-2025-14847 (MongoBleed)

Datart v1.0.0-rc.3 JDBC Connection String Injection Leading to Arbitrary File Read

Proof-of-concept exploit for CVE-2023-1454, an unauthenticated SQL injection vulnerability in JeecgBoot v3.5.0, enabling database extraction and…

WordPress WP-Advanced-Search <= 3.3.9 - Unauthenticated SQL Injection

POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method

SQL Injection vulnerability in NASA EOSDIS MODAPS due to improper input validation in the `category` parameter. This flaw allows attackers to…

CVE-2021-42670 - SQL Injection vulnerability in the Engineers online portal system.

Ghost CMS Content API Blind SQL Injection

CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit

FOGProject Authentication bypass CVE-2025-58443 Exploit