
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Exploit toolkit for CVE-2023-26258 targeting ArcServe backup software. Includes network scanner, credential extractor from database and registry,…

Python exploit for CVE-2019-14314: authenticated SQL injection in NextGEN Gallery 3.2.10 WordPress plugin, extracting password hashes from the…

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

Proof-of-concept exploit for CVE-2020-2969 targeting unauthorized access to Oracle Database password hashes. Enables security researchers to test and…

Windows Oracle Database Attack Toolkit

wpsqli full SQLi extractor + dumper for CVE-2026-60137

MSDAT: Microsoft SQL Database Attacking Tool

InfluxDB CVE-2019-20933 vulnerability exploit

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…

CVE-2012-2122 - MySQL Authentication Bypass

ZenoMinder Blind SQL Injection PoC