An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with sql-injection

A curated list of projects in awesome lists tagged with sql-injection .

https://github.com/chaitin/safeline

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

api-gateway application-security appsec blueteam bruteforce captcha cve cybersecurity firewall hackers http-flood security self-hosted sql-injection vulnerability waf web-application-firewall web-security websecurity xss

Last synced: 14 May 2025

https://github.com/chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

api-gateway application-security appsec blueteam bruteforce captcha cve cybersecurity firewall hackers http-flood security self-hosted sql-injection vulnerability waf web-application-firewall web-security websecurity xss

Last synced: 25 Mar 2025

https://github.com/digininja/dvwa

Damn Vulnerable Web Application (DVWA)

dvwa hacking infosec php security sql-injection training

Last synced: 12 May 2025

https://github.com/digininja/DVWA

Damn Vulnerable Web Application (DVWA)

dvwa hacking infosec php security sql-injection training

Last synced: 27 Mar 2025

https://github.com/ethicalhack3r/DVWA

Damn Vulnerable Web Application (DVWA)

dvwa hacking infosec php security sql-injection training

Last synced: 01 Apr 2025

https://github.com/andresriancho/w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.

appsec cross-site-scripting scanner security sql-injection

Last synced: 14 May 2025

https://github.com/1n3/intruderpayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

attack bugbounty burpsuite burpsuite-engagement burpsuite-intruder fuzz fuzz-lists fuzzing injection intruder payloads sql-injection

Last synced: 24 Mar 2025

https://github.com/1N3/IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

attack bugbounty burpsuite burpsuite-engagement burpsuite-intruder fuzz fuzz-lists fuzzing injection intruder payloads sql-injection

Last synced: 13 Mar 2025

https://github.com/kleiton0x00/Advanced-SQL-Injection-Cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

cheatsheet mssql-dump mysql-injection mysqldump sql sql-injection

Last synced: 14 Mar 2025

https://github.com/kleiton0x00/advanced-sql-injection-cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

cheatsheet mssql-dump mysql-injection mysqldump sql sql-injection

Last synced: 26 Mar 2025

https://github.com/palahsu/ddos-ripper

DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

attack-defense attack-server ddos ddos-attack ddos-attack-tool ddos-attack-tools ddos-attacks ddos-protection ddos-ripper ddos-tool deface-website denial-of-service hacking-tool hacking-tools internet-traffic linux-tools protection security sql-injection web-security

Last synced: 14 May 2025

https://github.com/palahsu/DDoS-Ripper

DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

attack-defense attack-server ddos ddos-attack ddos-attack-tool ddos-attack-tools ddos-attacks ddos-protection ddos-ripper ddos-tool deface-website denial-of-service hacking-tool hacking-tools internet-traffic linux-tools protection security sql-injection web-security

Last synced: 06 Apr 2025

https://github.com/ron190/jsql-injection

jSQL Injection is a Java application for automatic SQL database injection.

ctf-tools devops docker hacking hibernate java kali-linux pentest sonarcloud spock spring-boot sql-injection

Last synced: 18 Dec 2025

https://github.com/swisskyrepo/graphqlmap

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

capture-the-flag ctf fuzz graphql graphql-injection hacktoberfest nosql-injection pentest sql-injection

Last synced: 15 May 2025

https://github.com/swisskyrepo/GraphQLmap

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

capture-the-flag ctf fuzz graphql graphql-injection hacktoberfest nosql-injection pentest sql-injection

Last synced: 02 Apr 2025

https://github.com/janusec/janusec

JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。

acme application-gateway application-security cookie-banner cookie-compliance gateway golang gslb janusec janusec-application-gateway k8s-ingress-controller load-balance port-forwarding security sql-injection waf web-application-firewall web-application-security web-ssh

Last synced: 13 Apr 2025

https://github.com/Janusec/Application-Gateway

JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。

acme application-gateway application-security cookie-banner cookie-compliance gateway golang gslb janusec janusec-application-gateway k8s-ingress-controller load-balance port-forwarding security sql-injection waf web-application-firewall web-application-security web-ssh

Last synced: 05 Apr 2025

https://github.com/Janusec/janusec

JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。

acme application-gateway application-security cookie-banner cookie-compliance gateway golang gslb janusec janusec-application-gateway k8s-ingress-controller load-balance port-forwarding security sql-injection waf web-application-firewall web-application-security web-ssh

Last synced: 30 Mar 2025

https://github.com/safe3/uuwaf

An industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.

api-gateway api-security application-security data-mask ddos hips modsecurity nginx owasp rasp security sql-injection uusec uusec-waf uuwaf waap waf web-application-firewall web-security-gateway xss

Last synced: 18 Jun 2025

https://github.com/robotshell/magicRecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.

bash-script bug bugbounty bugbounty-tool bugbountytricks infosec nuclei scanner sql-injection subdomain subdomains-enumeration tool vulnerability-scanners xss-vulnerability

Last synced: 07 Apr 2025

https://github.com/robotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.

bash-script bug bugbounty bugbounty-tool bugbountytricks infosec nuclei scanner sql-injection subdomain subdomains-enumeration tool vulnerability-scanners xss-vulnerability

Last synced: 12 Apr 2025

https://github.com/nim4/DBShield

Database firewall written in Go

database db2 golang mariadb mysql oracle postgresql sql-injection

Last synced: 19 Apr 2025

https://github.com/nim4/dbshield

Database firewall written in Go

database db2 golang mariadb mysql oracle postgresql sql-injection

Last synced: 05 Apr 2025

https://github.com/YagamiiLight/Cerberus

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能

bypass hacking-tool middleware penetration-testing proxy python security-tools sql-injection ssrf waf websecurity xss

Last synced: 15 May 2025

https://github.com/ning1022/SQLInjectionWiki

一个专注于聚合和记录各种SQL注入方法的wiki

mssql mysql oracle sql-injection sqlserver wiki

Last synced: 02 Apr 2025

https://github.com/ning1022/sqlinjectionwiki

一个专注于聚合和记录各种SQL注入方法的wiki

mssql mysql oracle sql-injection sqlserver wiki

Last synced: 04 Apr 2025

https://github.com/chushuai/wscan

Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.

cel-go chromedp crawler headless martian passive-vulnerability-scanner poc sql-injection subdomains testwaf vulnerability-scanner waf webscan wscan xss

Last synced: 11 Jul 2025

https://github.com/s-shemmee/SQL-101

Get started with SQL database programming. This beginner's guide provides step-by-step tutorials, practical examples, exercises, and resources to master SQL. Let's unlock the power of data with SQL!

data-analysis data-science sql sql-challenges sql-commands sql-database sql-injection sql-server

Last synced: 27 Aug 2025

https://github.com/s-shemmee/sql-101

Get started with SQL database programming. This beginner's guide provides step-by-step tutorials, practical examples, exercises, and resources to master SQL. Let's unlock the power of data with SQL!

data-analysis data-science sql sql-challenges sql-commands sql-database sql-injection sql-server

Last synced: 05 Apr 2025

https://github.com/swisskyrepo/DamnWebScanner

Another web vulnerabilities scanner, this extension works on Chrome and Opera

extension lfi plugin polyglot-vector rce scans sql-injection web-vulnerabilities-scanner webbrowser xss-vulnerability

Last synced: 11 Jul 2025

https://github.com/swisskyrepo/damnwebscanner

Another web vulnerabilities scanner, this extension works on Chrome and Opera

extension lfi plugin polyglot-vector rce scans sql-injection web-vulnerabilities-scanner webbrowser xss-vulnerability

Last synced: 05 Apr 2025

https://github.com/zt2/sqli-hunter

SQLi-Hunter is a simple HTTP / HTTPS proxy server and a SQLMAP API wrapper that makes digging SQLi easy.

detection exploitation pentesting ruby sql-injection sqlmap vulnerability-scanner

Last synced: 02 Apr 2025

https://github.com/RisingStack/protect

Proactively protect your Node.js web services

express nodejs security sql-injection xss

Last synced: 03 Apr 2025

https://github.com/risingstack/protect

Proactively protect your Node.js web services

express nodejs security sql-injection xss

Last synced: 04 Apr 2025

https://github.com/JohnTroony/Blisqy

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

appsec blind-sql-injection blisqy database-security exploitation john-ombagi sql sql-injection sql-payloads

Last synced: 12 Jul 2025

https://github.com/presidentbeef/inject-some-sql

Have fun injecting SQL into a Ruby on Rails application!

rails ruby ruby-on-rails security sql-injection sqli

Last synced: 07 Apr 2025

https://github.com/OSTEsayed/OSTE-Meta-Scan

The OSTE meta scanner is a comprehensive web vulnerability scanner that combines multiple DAST scanners, including Nikto Scanner, ZAP, Nuclei, SkipFish, and Wapiti.

cybersecurity os-command-injection sql-injection tool vulnerability-detection web-vulnerability-scanner xss-detection

Last synced: 30 Aug 2025

https://github.com/petdance/bobby-tables

bobby-tables.com, the site for preventing SQL injections

bobby-tables hacktoberfest sql sql-injection

Last synced: 05 Apr 2025

https://github.com/youki992/VscanPlus

[VscanPlus内外网漏洞扫描工具]已更新HW热门漏洞检测POC。基于veo师傅的漏扫工具vscan二次开发的版本,端口扫描、指纹检测、目录fuzz、漏洞扫描功能工具,批量快速检测网站安全隐患。An open-source, cross-platform website vulnerability scanning tool that helps you quickly detect website security vulnerabilities.

fingerprint fuzzing nuclei portscan security sql-injection xray

Last synced: 07 Sep 2025

https://github.com/SecAegis/SecReport

ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。

ai chatgpt collaboration collaborations docker openai pentest privacy rce report retest sec security security-tools sql-injection vulnerabilities web-security xss

Last synced: 07 Sep 2025

https://github.com/secaegis/secreport

ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。

ai chatgpt collaboration collaborations docker openai pentest privacy rce report retest sec security security-tools sql-injection vulnerabilities web-security xss

Last synced: 11 Jun 2025

https://github.com/sec-report/secreport

ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。

ai chatgpt collaboration collaborations docker openai pentest privacy rce report retest sec security security-tools sql-injection vulnerabilities web-security xss

Last synced: 05 Apr 2025

https://github.com/laurent22/so-sql-injections

SQL injection vulnerabilities in Stack Overflow PHP questions

mysql php sql-injection

Last synced: 12 Jun 2025

https://github.com/guanguans/soar-php

SQL optimizer and rewriter(assisted SQL tuning). - SQL 优化器和重写器(辅助 SQL 调优)。

debugbar mysql optimizer rewriter soar sql sql-alchemy sql-injection sql-optimizer sql-query sql-rewriter sql-tuning sqlalchemy tuning

Last synced: 08 Apr 2025

https://github.com/terjanq/flag-capture

Solutions and write-ups from security-based competitions also known as Capture The Flag competition

capture-the-flag competition csrf css-injection ctf sql-injection ssrf web xss-injection

Last synced: 12 Oct 2025

https://github.com/keramas/mssqli-duet

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

active-directory application-security burp-extensions burp-plugin mssql penetration-testing sql-injection user-enumeration windows

Last synced: 19 Oct 2025

https://github.com/Keramas/mssqli-duet

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

active-directory application-security burp-extensions burp-plugin mssql penetration-testing sql-injection user-enumeration windows

Last synced: 02 Apr 2025

https://github.com/himadriganguly/sqlilabs

Lab set-up for learning SQL Injection Techniques

learning-sql-injection php restore-database sql-injection

Last synced: 16 Nov 2025

https://github.com/the-c0d3r/sqli-scanner

A tool to mass scan SQL Injection Vulnerable websites from a file.

scanner sql-injection

Last synced: 25 Dec 2025

https://github.com/ronin-rb/ronin-vulns

Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.

hacktoberfest lfi open-redirect pentest-tool pentesting rfi ronin-rb ruby security sql-injection sqli ssti vulnerability-detection vulnerability-scanners web-security xss

Last synced: 05 Apr 2025

https://github.com/arvindshmicrosoft/sqlscriptdomsamples

Samples showing how to use Microsoft.SqlServer.TransactSql.ScriptDom classes

antlr azuresql code-formatter csharp dotnet hacktoberfest parsing scriptdom sql-injection sql-server sqldom t-sql visitor-pattern

Last synced: 15 Apr 2025

https://github.com/aikidosec/firewall-node

Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.

attack-defense firewall nodejs nosql-injection path-traversal rasp security shell-injection sql-injection

Last synced: 05 Apr 2025

https://github.com/arvindshmicrosoft/SQLScriptDomSamples

Samples showing how to use Microsoft.SqlServer.TransactSql.ScriptDom classes

antlr azuresql code-formatter csharp dotnet hacktoberfest parsing scriptdom sql-injection sql-server sqldom t-sql visitor-pattern

Last synced: 11 May 2025

https://github.com/Sunlight-Rim/SQLbit

Just another script for automatize boolean-based blind SQL injections. (Demo)

pentesting sql sql-injection

Last synced: 12 Jul 2025

https://github.com/AikidoSec/firewall-node

Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.

attack-defense firewall nodejs nosql-injection path-traversal rasp security shell-injection sql-injection

Last synced: 08 Mar 2025

https://github.com/xploits3c/dorkeye

DorkEye is a Python script for ethical dorking. The goal is to identify unintentionally exposed resources, such as sensitive files, login panels or indexed directories.

admin cybersecurity dork dorking-list dorking-tool duckduckgo duckduckgo-dork duckduckgo-search google google-dork google-dorks hacker hacking osint python3 sql-injection sql-server vulnerabilities vulnerability-detection xss-injection

Last synced: 05 Nov 2025

https://github.com/Saluki/joi-security

Detect security flaws in Joi validation schemas (XSS, SQL injection, ...) 🔥

audits hapi joi js security sql-injection typescript validation web-security xss

Last synced: 05 Mar 2025

https://github.com/kongbytes/joi-security

Detect security flaws in Joi validation schemas (XSS, SQL injection, ...) 🔥

audits hapi joi js security sql-injection typescript validation web-security xss

Last synced: 25 Dec 2025

https://github.com/corazawaf/libinjection-go

libinjection is a Golang port of the libinjection(https://github.com/client9/libinjection)

coraza-waf go golang libinjection owasp sql-injection waf xss

Last synced: 13 Apr 2025

https://github.com/wukaipeng-dev/netsecurity

网络安全训练营全部资料,包括 Web 安全、网络安全、信息安全、系统防护、攻防渗透、云安全

csrf net-security sql-injection xss

Last synced: 27 Oct 2025

https://github.com/rummykhan/sql-nightmare

SQL SERVER Exploitation.

sql-injection sql-server

Last synced: 06 May 2025

https://github.com/paulveillard/cybersecurity-web-security

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Web Security in Cybersecurity.

cyber-threat-intelligence cybersecurity-assessments ddos ddos-attacks security-tools services sql-injection web website xss-attacks xss-detection xss-scanner xss-vulnerability

Last synced: 28 Mar 2025

https://github.com/sharafdin/blackSQL

blackSQL – Automate SQL Injection detection with ease! Scan, exploit, and bypass WAFs. Ethical hacking made simple.

blacksql hacking sql-injection sqli

Last synced: 01 Apr 2025

https://github.com/ahmedosamamath/sqli-dorks-generator

Python-based Google dork generator that creates search patterns for web reconnaissance. Combines custom patterns, site lists, and search parameters to generate comprehensive dork lists for security research.

dorks sql-injection

Last synced: 14 May 2025

https://github.com/may215/koa-protect

Security module for koa applications

koa nodejs security sql-injection xss

Last synced: 10 Jul 2025

https://github.com/akshatvg/vulnerability-testing-solutions

Website for testing and preventing different attacks like XSS, SQL Injection & Spoofing for Nasscom (ISAA) Project.

audit cyber-security security spoofing sql-injection testing vulnerability website xss

Last synced: 11 Apr 2025

https://github.com/inforkgodara/sql-injection

It is a SQL injection vulnerable project with demonstration. It is developed using PHP and MySQL technologies. It also contains a youtube link where fully demonstrated SQL Injection.

attack bypass-login bypass-login-php-website login-form-hacking mysql-database php php-login-form php-small-project php-sql-injection php-web-injection sql-database sql-injection sql-injection-attacks sql-injection-exploitation

Last synced: 21 Jul 2025

https://github.com/the404hacking/dsss

Damn Small SQLi Scanner. (DSSS)

damn dsss scanner sql sql-injection sqli sqlmap the404hacking

Last synced: 13 May 2025