
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Strafer: A tool to detect potential infections in Elasticsearch instances

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

poc for CVE-2025-14847

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

POCs to demonstrate CVE-2026-42167 in ProFTPD

Apache CouchDB 3.2.1 - Remote Code Execution (RCE)

ISR-sqlget It's a blind SQL injection tool developed in Perl.

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

Django QuerySet.annotate(), aggregate(), extra() SQL 注入

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)

AuthBypass & Auto Backdooring Devices