
CVE-2026-52887-NocoBase-SQLi-RCE
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

A collection of web pages vulnerable to SQL injection flaws

🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.

Proof-of-concept exploit for CVE-2025-24999, demonstrating privilege escalation in Microsoft SQL Server via the MS_DatabaseManager role.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Proof-of-concept exploit for CVE-2025-14847, a MongoDB zlib decompression vulnerability that leaks uninitialized server memory via crafted BSON…

PoC for CVE-2021-2471 - XXE in MySQL Connector/J

Security advisory for CVE-2026-30655: unauthenticated SQL injection in esiclivre (/reset/index.php).

CVE-2025-14847 MongoDB Memory Leak Exploit

SQL Injection vulnerability discovered in Grocery Store Management System 1.0

CVE-2023-45503 Reference

SQL Injection vulnerability in NASA EOSDIS MODAPS due to improper input validation in the `category` parameter. This flaw allows attackers to…

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

CVE-2026-72898

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection