
CVE-2026-40083
Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…

Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…


A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

Automated testing to find logic and performance bugs in database systems

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

CVE-2012-2122 MySQL Authentication Bypass Home Lab

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…

Student Management System using PHP and MySQL

GYM management system using PHP and MYSQL

Web-Security-Learning

Grafana SQL Expressions Arbitrary File Write to RCE

CVE-2024-22369 Reproducer

CVE-2023-21971 Connector/J RCE Analysis分析

CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in…

Advisory and proof-of-concept for CVE-2026-29861, a critical SQL injection in PHP-MYSQL-User-Login-System allowing unauthenticated admin access.

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

Sequelize Sql Injection 취약점 구현

若依4.2 (Shiro 1.4.1) Shiro-721 (CVE-2019-12422)漏洞复现环境