unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
BiiTts/CVE-2026-72001-Pangolin-Cross-Org-Auth-Bypass
PoC for CVE-2026-72001 — Pangolin < 1.22.0 cross-organization resource authentication bypass via the share-link access-token endpoint (CWE-639, CVSS 8.1).
Create: 2026-09-24 19:54:24 +0000 UTC Push: 2026-09-24 19:54:29 +0000 UTC |
watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127
Create: 2026-09-24 19:22:13 +0000 UTC Push: 2026-09-24 19:29:50 +0000 UTC |
Hassham1/CVE-2026-12227-visualcomposer-lfi-poc
CVE-2026-12227 - Visual Composer <= 45.16.0 unauthenticated LFI via vcv-template (CVSS 9.8): Docker validation lab, safe-oracle PoC, nuclei template. Root cause: validate-then-mutate on the theme: prefix. Verified: vendor fix never landed - fires through 45.16.3 on WP <= 7.1.1; masked by WP 7.1.2 core gate.
Create: 2026-09-24 17:44:25 +0000 UTC Push: 2026-09-24 17:44:26 +0000 UTC |
anthonyk2923/CVE-2026-94609
CVE-2026-94609: Writeup and POC
Create: 2026-09-24 17:32:31 +0000 UTC Push: 2026-09-24 17:48:20 +0000 UTC |
murrez/CVE-2026-12227
CVE-2026-12227 (CVSS 9.8): WordPress Visual Composer Website Builder ≤45.16.0 — unauthenticated local file inclusion via vcv-template. Educational PoC only.
Create: 2026-09-24 17:11:35 +0000 UTC Push: 2026-09-24 17:12:02 +0000 UTC |
rushikesh-a-bhujbal/CVE-2010-2075
UnrealIRCd 3.2.8.1 backdoor exploit — reverse shell via AB; trigger, built from scratch in Python using raw sockets. No Metasploit.
Create: 2026-09-24 16:39:01 +0000 UTC Push: 2026-09-24 16:39:02 +0000 UTC |
BardLaudian/CVE-2023-49070
Apache OFBiz XML-RPC pre-auth deserialization RCE PoC (CVE-2023-49070) — auth bypass + ysoserial gadget chain via /webtools/control/xmlrpc
Create: 2026-09-24 16:29:42 +0000 UTC Push: 2026-09-24 16:29:43 +0000 UTC |
d154573r-4v3r73d/CVE-2024-47875
Create: 2026-09-24 16:09:34 +0000 UTC Push: 2026-09-24 16:09:35 +0000 UTC |
nihan-silent-reign/CVE-2026-43284-DIRTY-FRAG-
Detailed technical analysis of CVE-2026-43284 (Dirty Frag) local privilege escalation flaw in the Linux kernel.
Create: 2026-09-24 14:51:32 +0000 UTC Push: 2026-09-24 14:51:33 +0000 UTC |
khaleedbt/netis-cve-2026-36539
Скрипт проверки роутеров Netis
Create: 2026-09-24 14:25:58 +0000 UTC Push: 2026-09-24 14:25:59 +0000 UTC |
zyphorixofficialmain-lab/cve-2026-87902
Create: 2026-09-24 14:02:40 +0000 UTC Push: 2026-09-24 14:02:41 +0000 UTC |
whoami-012/CVE-2026-96515
Create: 2026-09-24 12:54:43 +0000 UTC Push: 2026-09-24 12:54:44 +0000 UTC |
RaniaMathlouthi/cve-2017-9805-struts-lab
Create: 2026-09-24 11:58:03 +0000 UTC Push: 2026-09-24 11:58:04 +0000 UTC |
yulisec/CVE-2026-90817
Create: 2026-09-24 07:37:07 +0000 UTC Push: 2026-09-24 07:37:08 +0000 UTC |
yulisec/CVE-2025-7771
Create: 2026-09-24 07:23:53 +0000 UTC Push: 2026-09-24 07:23:54 +0000 UTC |
michel2342/CVE-2026-YYYYY-Victor8
Create: 2026-09-24 05:39:17 +0000 UTC Push: 2026-09-24 05:39:18 +0000 UTC |
TaiYou-chtsec/CVE-2026-87902-PoC
Create: 2026-09-24 03:37:51 +0000 UTC Push: 2026-09-24 03:37:52 +0000 UTC |
cflowsec/cve-2026-94504
Ninja Forms unauth stored XSS POC
Create: 2026-09-24 01:07:12 +0000 UTC Push: 2026-09-24 01:07:13 +0000 UTC |
fl0ydsec/CVE-2026-63030
WP2Shell - CVE-2026-63030 + CVE-2026-60137 WordPress Core pre-auth RCE mass exploit
Create: 2026-09-24 01:04:05 +0000 UTC Push: 2026-09-24 01:04:10 +0000 UTC |
petermalone/CVE-2026-84543
Technical disclosure and PoC for CVE-2026-84543, a macOS SMB kernel out-of-bounds access fixed by Apple
Create: 2026-09-24 00:22:30 +0000 UTC Push: 2026-09-24 02:47:44 +0000 UTC |
Previous
-111
-110
-109
-108
-107
-106
-105
-104
Next