
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

Proof-of-concept exploit for time-based blind SQL injection in Bacula-Web's jobfiles endpoint, using pg_sleep() delays to extract PostgreSQL version…

Customer Support System 1.0 - SQL Injection Vulnerability in manage_department.php via "id" URL Parameter

Non-destructive PostgreSQL vulnerability checker for CVE-2026-6471. Audits server version and REPLICATION privileges to identify exposure to logical…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953

Technical disclosure and proof-of-concept for SQL injection in PuneethReddyHC event-management v1.0, detailing affected endpoint, payloads, and…

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

OpenEMR Security issue

version between CVE-2018-20433 and CVE-2019-5427