
CVE-2021-21311
Proof-of-concept for CVE-2021-21311, a server-side request forgery in Adminer before 4.7.9, demonstrating SSRF exploitation in PHP database…

Proof-of-concept for CVE-2021-21311, a server-side request forgery in Adminer before 4.7.9, demonstrating SSRF exploitation in PHP database…

Python-based proof-of-concept exploit for CVE-2025-5840 targeting file upload vulnerabilities in database management systems, enabling remote command…

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Proof of concept for authenticated SQL injection in Coaching Management System, demonstrating database dump via unsanitized complaintreply parameter.

Proof-of-concept demonstrating authenticated SQL injection in College Management System 1.0 via the 'course_code' parameter, with boolean-based blind…

Proof-of-concept exploit for CVE-2024-10354: SQL injection in SourceCodester Petrol Pump Management Software v1.0. Demonstrates unauthenticated…

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Authenticated SQL injection exploit for Royal Event Management System 1.0 via the 'todate' parameter, with proof-of-concept payloads and SQLmap…

Proof-of-concept for CVE-2024-30998: SQL injection vulnerability in PHPGurukul Men Salon Management System 2.0 via the email parameter, enabling…

Exploit blind SQL Injection in (Online Learning Management System)

Proof-of-concept for CVE-2024-48427: SQL injection in Sourcecodester Packers and Movers Management System v1.0. Exploits the id parameter to execute…

Unauthenticated SQL injection exploit for GLPI versions before 10.0.18, enabling database enumeration, credential extraction, and API token…

Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

MicroWeber Unauthenticated User Database Disclosure - CVE-2020-13405

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…