
CVE-2026-2005
PoC for CVE-2026-2005

PoC for CVE-2026-2005

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

ISR-sqlget It's a blind SQL injection tool developed in Perl.

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

wpsqli full SQLi extractor + dumper for CVE-2026-60137



CVE-2026-1337 - Neo4j - Log Injection

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

chusa - 注射 - the new generation of sqlmap

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…


CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit

CVE-2021-27928-POC