
postgres-bruteforcer
This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

Open-source, cross-platform, multi-purpose security auditing tool

PHP Webshell with handy features

SolarWinds Orion Account Audit / Password Dumping Utility

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Automated testing to find logic and performance bugs in database systems

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Windows Oracle Database Attack Toolkit

Detection Script for MongoBleed Exploitation

Detect security issues, large or small, in a CouchDB server

Detect security issues in an Apache CouchDB server

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)