
CVE-2026-63030-POC
Proof-of-concept exploit for CVE-2026-63030 (WordPress pre-auth RCE) with SQL injection detection, credential extraction, and webshell deployment.…

Proof-of-concept exploit for CVE-2026-63030 (WordPress pre-auth RCE) with SQL injection detection, credential extraction, and webshell deployment.…

Time Based SQL Injection in Zabbix Server Audit Log --> RCE

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Automated proof-of-concept exploit for unauthenticated SQL injection in FortiWeb; abuses the Authorization header to write a webshell and execute…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Offensive MSSQL toolkit written in Python, based off SQLRecon

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Python exploit for CVE-2022-24706 targeting Apache CouchDB 3.2.1 and below, achieving remote code execution via Erlang cookie authentication bypass.

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…

Automated exploit tool for WordPress REST API SQL injection (CVE-2026-63030/CVE-2026-60137) with time-based blind detection, credential extraction,…

Ivanti EPM SQL Injection Remote Code Execution Vulnerability

Unauthenticated SQL injection and arbitrary file upload exploit chain for FreePBX 16, achieving remote code execution via admin creation and webshell…

Proof-of-concept exploit for CVE-2026-6433: unauthenticated SQL injection to remote code execution in WordPress FlipperCode plugin. Python 3 script…

CVE-2024-43468 SCCM SQL Injection Exploit (mTLS unextractable client cert from MacOS keychain version)

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

Unauthenticated SQL injection to root RCE exploit for FreePBX CVE-2025-57819, chaining SQLi, cron webshell, and incron fwconsole hook for full…