
sqlancer
Automated testing to find logic and performance bugs in database systems

Automated testing to find logic and performance bugs in database systems

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

Reproduces and analyzes CVE-2026-3494, an audit logging bypass in MariaDB server_audit plugin, using Docker-based multi-version testing to compare…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料

A critical SQL Injection vulnerability (CVE-2025-25964) discovered in the School Information Management System v1.0

CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads,…

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

CVE-2025-14847 mongobleed python file

Proof-of-concept exploit for CVE-2025-67644, a SQL injection vulnerability in LangGraph SQLite Checkpoint. Demonstrates arbitrary SQL injection via…

CVE-2022-33171: TypeORM SQL Injection Vulnerability

Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of…

Reverse-engineered docs and tools for 8BitDo firmware encryption

Key Negotiation Of Bluetooth (KNOB) attacks on Bluetooth BR/EDR and BLE [CVE-2019-9506]

RISC-V ISA extension for hardware-enforced secret computation using ML-KEM-512 key encapsulation and SIMON-128 encryption, enabling data-oblivious…

Analysis of DataDome's custom obfuscated VM and bytecode format, revealing string encryption, S-box ciphers, and browser fingerprinting signals for…

Encryption from Nonlinear Sheaf Morphisms over Graphs

BitLocker full-disk encryption bypass research using CVE-2023-21563 (BitPixie). Methodology, exploit chain, and defensive recommendations.