
sqlancer
Automated testing to find logic and performance bugs in database systems

Automated testing to find logic and performance bugs in database systems

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

A database of RAT collected from Internet

Proof-of-concept exploit for CVE-2024-53522, demonstrating decryption of HOSxP XE database credentials using a static hard-coded private key-IV.

Stored XSS via User-Agent in Admin Order View in PhocaCart

A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of…

Proof-of-concept exploit for CVE-2025-67644, a SQL injection vulnerability in LangGraph SQLite Checkpoint. Demonstrates arbitrary SQL injection via…

risorse di ricerca per cve-2026-7228

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Move Vulnerability Database

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission…

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

CVE-2025-9776 — CatFolders WordPress Plugin: Authenticated SQL Injection via CSV Import | POC + Walkthrough