
CVE-2025-14847
This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.

Un semplice exploit che sfrutta CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858 per elencare gli utenti con la psw del db

CVE-2024-57430: PHPJabbers Cinema Booking System v2.0 is vulnerable to SQL injection, leading to unauthorized data access and privilege escalation.

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

Redis UAF RCE PoC collection for CVE-2026-23479: safe version checker, exploit module, GDB-assisted PoC, and Sigma detection rules for authorized…

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…


Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

A tool for exploring Firebase datastores.

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

Hunt Open MongoDB instances

An modular asset discovery framework written in python to automate the repeating manual work


PoC for CVE-2026-2005

Strafer: A tool to detect potential infections in Elasticsearch instances

PoC of CVE-2022-24707