
b374k
PHP Webshell with handy features

PHP Webshell with handy features

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Exploit tool for CVE-2025-64459, targeting SQL injection vulnerabilities in Django applications. Enables automated testing and exploitation of…

Automated NoSQL database enumeration and web application exploitation tool.

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

A tool for exploring Firebase datastores.

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Python tool for exploiting CVE-2021-35616

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

golang test tool for mongobleed (cve-2025-14847)

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Free universal database tool and SQL client

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

SolarWinds Orion Account Audit / Password Dumping Utility

A new open-source tool to quickly audit SAP permissions.