
mongoaudit
🔥 A powerful MongoDB auditing and pentesting tool 🔥

🔥 A powerful MongoDB auditing and pentesting tool 🔥

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production


mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402


CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner


Proof-of-concept exploit for CVE-2023-49496, demonstrating SQL injection in UCServer via the /login/wwx_corpInfo/ endpoint to extract sensitive…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.

Module for PrestaShop 1.6.1.X/1.7.X to fix CVE-2022-31181 / CVE-2022-36408 vulnerability (Chain SQL Injection)

Checks for exposed Redis servers

Proof-of-concept exploit for CVE-2021-35576 demonstrating bypass of Oracle Unified Audit policy via a security vulnerability in database auditing.

CVE-2025-29705