
CVE-2026-76904
POC | GeoServer Unauthenticated SQL injection to complete RCE

POC | GeoServer Unauthenticated SQL injection to complete RCE

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

Learning and hunting SQL injection bugs for 50 continuous days

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

Educational PoC lab for Redis CVE-2025-49844 (RediShell), a use-after-free in the Lua interpreter; Dockerized vulnerable instance and modular RCE…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

PoC exploit for CVE-2026-58048, an authenticated cPanel SQL injection that escalates to MySQL root and supports file-read, webshell, and RCE payloads.

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

Proof-of-concept exploit for CVE-2021-35042, a Django SQL injection vulnerability in QuerySet.order_by(), with Docker-based lab environment for…

Detailed analysis and reproduction guide for CVE-2026-8054, a pre-auth SQL injection in dotCMS Publish Audit API, including exploit payloads, Docker…

Proof-of-concept for CVE-2026-65761: unauthenticated SQL injection via filter_sortby in EasyStore Joomla, with Docker lab for testing and patching.

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

PoC exploit for CVE-2024-9264: Grafana SQL Expression vulnerability enabling local file inclusion and remote code execution via DuckDB SQL injection.…

Educational Python 3 proof-of-concept for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple <= 2.2.9. Adapted for CTF/lab use with…