
CVE-2026-76904
POC | GeoServer Unauthenticated SQL injection to complete RCE

POC | GeoServer Unauthenticated SQL injection to complete RCE

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Proof-of-concept exploit for pgAdmin 4 Import/Export RCE (CVE-2026-17566) abusing a backslash-escape mismatch to inject `\copy TO PROGRAM`, letting a…

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Exploit script for CVE-2026-41462, a critical unauthenticated stacked SQL injection in ProjeQtor ≤12.4.3. Creates admin accounts via crafted…

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

Proof-of-concept exploit for SQL injection in BigAnt Office Messenger 5.6.06 enabling remote code execution via stacked queries and webshell upload.

Proof-of-concept exploit for CVE-2021-27928, demonstrating remote code execution in MariaDB/MySQL via wsrep_provider eval injection, with msfvenom…

Ruby-based MySQL client for penetration testing with SQL shell, database management, file read/write, PHP command/reverse shells, and a Linux MySQL…

SQL injection exploit for Joomla JCK Editor 6.4.4 (CVE-2018-17254) that dumps admin credentials and optionally uploads a PHP RCE shell via stacked…

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit