
LDAP-Password-Hunter
Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Automated NoSQL database enumeration and web application exploitation tool.

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Exploit tool for CVE-2025-64459, targeting SQL injection vulnerabilities in Django applications. Enables automated testing and exploitation of…

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Automated testing to find logic and performance bugs in database systems

🔥 A powerful MongoDB auditing and pentesting tool 🔥

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

golang test tool for mongobleed (cve-2025-14847)

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Windows Oracle Database Attack Toolkit

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information