
Blisqy
Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers

Automated XSS and SQLi vulnerability scanner that crawls web applications, tests every link and form for cross-site scripting and SQL injection, with…

Automated security scanner for websites built with JavaScript module bundlers like Webpack. Extracts APIs from bundled JS and tests for SQL…

Structure-aware JSON fuzzer that generates valid mutated JSON objects with injection payloads for SQL, command, LDAP, NoSQL, and other…

Automated testing to find logic and performance bugs in database systems

Go-based web application fuzzer and scanner with template-driven requests, custom encoder/decoder support, and a JavaScript extension API for…

Command Injection Web Fuzzer Script for mitmproxy

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Educational research tool demonstrating CVE-2025-14847 memory disclosure in MongoDB's BSON decompression. Simulates bounds-checking failures and…

This repo contains my python script version of CVE-2025-14847 (MongoBleed)