
CVE-2025-67261
Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the…

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the…

Summar Employee Portal Prior to 3.98.0 Authenticated SQL Injection - CVE-2025-40677

Python program to dump all the databases, exploiting NagiosXI sqli vulnerability

Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

A tool to crash MySQL servers with CVE-2017-3599

A SQL injection vulnerability was discovered in the endpoint responsible for searching for platform clients. User input sent to the search parameter…

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods…

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Nexter <= 2.0.3 - Authenticated (Subscriber+) SQL Injection via 'to' and 'from'

CVE-2024-57430: PHPJabbers Cinema Booking System v2.0 is vulnerable to SQL injection, leading to unauthorized data access and privilege escalation.

CVE-2024-40443 - A SQL Injection vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary SQL commands

A Poc for CVE-2020-24913, a SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an…

IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

Proof-of-concept exploit for CVE-2026-72898, targeting Toucan2 behavior with malformed map options to reproduce the vulnerability and validate…