unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
jvidhan/cve-2026-43687
Create: 2026-09-25 06:06:52 +0000 UTC Push: 2026-09-25 06:06:53 +0000 UTC |
murrez/CVE-2026-48842
Roundcube virtuser_query pre-auth SQLi (CVE-2026-48842). Python PoC — version detect, virtuser plugin, login probe. https://pocbit.org
Create: 2026-09-25 05:59:39 +0000 UTC Push: 2026-09-25 05:59:40 +0000 UTC |
pocbit/CVE-2026-48842
Roundcube virtuser_query pre-auth SQLi (CVE-2026-48842). Python PoC — version detect, virtuser plugin, login probe. https://pocbit.org
Create: 2026-09-25 05:59:18 +0000 UTC Push: 2026-09-25 06:00:18 +0000 UTC |
HORKimhab/CVE-2025-9974
CVE-2025-9974 - Draft or TODO
Create: 2026-09-25 04:09:16 +0000 UTC Push: 2026-09-25 04:09:21 +0000 UTC |
HORKimhab/CVE-2026-65660
CVE-2026-65660 - Draft or TODO
Create: 2026-09-25 03:22:53 +0000 UTC Push: 2026-09-25 03:22:57 +0000 UTC |
AthBe1337/CVE-2026-43499-poc
Create: 2026-09-25 02:45:58 +0000 UTC Push: 2026-09-25 02:45:59 +0000 UTC |
joaovicdev/EXPLOIT-CVE-2026-87902
Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE condicional). Uso educacional/autorizado.
Create: 2026-09-25 01:06:33 +0000 UTC Push: 2026-09-25 01:06:37 +0000 UTC |
connorjaydunn/CVE-2026-79417
CVE-2026-79417 PoC
Create: 2026-09-25 00:57:35 +0000 UTC Push: 2026-09-25 00:58:45 +0000 UTC |
khellwan/CVE-2026-87902---PoC-
Proof of concept for vulnerability CVE-2026-87902 in Wordpress
Create: 2026-09-25 00:56:30 +0000 UTC Push: 2026-09-25 00:56:32 +0000 UTC |
khellwan/CVE-2026-87902_PoC
Proof of concept for vulnerability CVE-2026-87902 in Wordpress
Create: 2026-09-25 00:56:30 +0000 UTC Push: 2026-09-25 00:58:30 +0000 UTC |
diyiqiuye/CVE-2025-21479-FX5P
Temporary root for OPPO Find X5 Pro (PFEM00) via CVE-2025-21479 + KernelSU LKM late-load (cloud-buildable)
Create: 2026-09-24 23:20:42 +0000 UTC Push: 2026-09-24 23:20:48 +0000 UTC |
n-WN/cve-2024-0402-lab-assets
Create: 2026-09-24 21:51:14 +0000 UTC Push: 2026-09-24 21:51:20 +0000 UTC |
BiiTts/CVE-2026-72001-Pangolin-Cross-Org-Auth-Bypass
PoC for CVE-2026-72001 — Pangolin < 1.22.0 cross-organization resource authentication bypass via the share-link access-token endpoint (CWE-639, CVSS 8.1).
Create: 2026-09-24 19:54:24 +0000 UTC Push: 2026-09-24 19:54:29 +0000 UTC |
watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127
Create: 2026-09-24 19:22:13 +0000 UTC Push: 2026-09-24 19:29:50 +0000 UTC |
Hassham1/CVE-2026-12227-visualcomposer-lfi-poc
CVE-2026-12227 - Visual Composer <= 45.16.0 unauthenticated LFI via vcv-template (CVSS 9.8): Docker validation lab, safe-oracle PoC, nuclei template. Root cause: validate-then-mutate on the theme: prefix. Verified: vendor fix never landed - fires through 45.16.3 on WP <= 7.1.1; masked by WP 7.1.2 core gate.
Create: 2026-09-24 17:44:25 +0000 UTC Push: 2026-09-24 17:44:26 +0000 UTC |
anthonyk2923/CVE-2026-94609
CVE-2026-94609: Writeup and POC
Create: 2026-09-24 17:32:31 +0000 UTC Push: 2026-09-24 17:48:20 +0000 UTC |
murrez/CVE-2026-12227
CVE-2026-12227 (CVSS 9.8): WordPress Visual Composer Website Builder ≤45.16.0 — unauthenticated local file inclusion via vcv-template. Educational PoC only.
Create: 2026-09-24 17:11:35 +0000 UTC Push: 2026-09-24 17:12:02 +0000 UTC |
rushikesh-a-bhujbal/CVE-2010-2075
UnrealIRCd 3.2.8.1 backdoor exploit — reverse shell via AB; trigger, built from scratch in Python using raw sockets. No Metasploit.
Create: 2026-09-24 16:39:01 +0000 UTC Push: 2026-09-24 16:39:02 +0000 UTC |
BardLaudian/CVE-2023-49070
Apache OFBiz XML-RPC pre-auth deserialization RCE PoC (CVE-2023-49070) — auth bypass + ysoserial gadget chain via /webtools/control/xmlrpc
Create: 2026-09-24 16:29:42 +0000 UTC Push: 2026-09-24 16:29:43 +0000 UTC |
d154573r-4v3r73d/CVE-2024-47875
Create: 2026-09-24 16:09:34 +0000 UTC Push: 2026-09-24 16:09:35 +0000 UTC |
Previous
-166
-165
-164
-163
-162
-161
-160
-159
Next