
MongoBLEED---CVE-2025-14847-POC-
This repo contains my python script version of CVE-2025-14847 (MongoBleed)

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

YARA malware query accelerator (web frontend)

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

A flaw was found in the Django package, which leads to a SQL injection. This flaw allows an attacker using a crafted dictionary containing malicious…

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

A low-privileged user can exploit this via a crafted order_by parameter, causing time-based blind SQL injection.

jackson unserialize

CVE-2021-27928-POC

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…