
CVE-2026-61511-PoC-Exploit
CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Python tool for exploiting CVE-2021-35616

Ultimate Member Unauthorized Database Access / SQLi

Chatwoot SQL injection in FilterService

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

ZenoMinder Blind SQL Injection PoC

CVE-2022-40032: Simple Task Managing System - 'login' and 'password' SQL Injection (Unauthenticated)

CVE-2019-5893 | OpenSource ERP application has SQL Injection vulnerability.

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

PoC of SQL Injection vul(CVE-2020-9483,Apache SkyWalking)

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

wpsqli full SQLi extractor + dumper for CVE-2026-60137

PostgreSQL pgcrypto heap buffer overflow PoC demonstrating CVE-2026-2005: low-privileged RCE and privilege escalation to superuser via crafted…

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.