
CVE-2024-34693
An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

CVE-2025-14847 explaination and lab

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only

Go proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a MongoDB memory disclosure vulnerability. Crafts malformed BSON documents to leak…

Demonstration of the SQL injection vulnerability in wordpress 5.8.2

Educational research tool demonstrating CVE-2025-14847 memory disclosure in MongoDB's BSON decompression. Simulates bounds-checking failures and…

Detailed security analysis and proof-of-concept for CVE-2022-3141, an unauthenticated SQL injection in ACS EDU 3rd Gen, including reproduction steps…

Proof-of-concept repository for CVE-2025-69216, an authenticated SQL injection in OpenSTAManager's Scadenzario print template, enabling extraction of…

Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

Proof-of-concept repository for CVE-2025-69213, demonstrating a SQL injection vulnerability in OpenSTAManager's ajax_complete.php endpoint with…

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

Working POC of CVE-2026-6664 written by Sonnet 4.6