

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department in Customer Support System 1.0 allow authenticated…

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods…

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

Django StringAgg SQL Injection (CVE-2020-7471)





CVE-2019-14900

PoC for CVE-2021-2471 - XXE in MySQL Connector/J

NodeJS + Postgres (Remote Code Execution) 🛰

Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization…

PoC for CVE-2022-34265