
firebaseExploiter
CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Modern Events Calendar Lite <= 7.33.0 — Unauthenticated SQL Injection

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers


remote code execute for redis4 and redis5

CVE-2021-27928 MariaDB/MySQL-'wsrep provider' 命令注入漏洞

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no…

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

jackson unserialize

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

CVE-2021-27928-POC