
sqlmap-ai
This script automates SQL injection testing using SQLMap with AI-powered decision making.

This script automates SQL injection testing using SQLMap with AI-powered decision making.

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

CVE discovery

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)


full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…


CVE-2024-54761 PoC

CVE-2021-27928-POC

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Exploit for Joomla JCK Editor 6.4.4 (CVE-2018-17254)

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection