unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
pentagon404uzb/CVE-2021-1675-Local-Privilege-Escalation-CVSS-7.8-
Create: 2026-09-25 12:04:55 +0000 UTC Push: 2026-09-25 12:04:56 +0000 UTC |
hacbs-release-tests/collectors-no-cve-81a1b206
Create: 2026-09-25 11:53:50 +0000 UTC Push: 2026-09-25 11:53:55 +0000 UTC |
AtlasVector/Kestra-cve-2026-53576
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common Docker-socket misconfiguration turns container-root into full host compromise.
Create: 2026-09-25 10:21:00 +0000 UTC Push: 2026-09-25 10:21:01 +0000 UTC |
roshanrajbanshi/cve-2023-25690-smuggler
Python exploit for CVE-2023-25690 — Apache HTTP Request Smuggling via CRLF injection in mod_rewrite/mod_proxy. Built and tested against TryHackMe's Contrabando box.
Create: 2026-09-25 09:23:01 +0000 UTC Push: 2026-09-25 09:23:02 +0000 UTC |
murrez/CVE-2026-93399
Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointments; bookly_rollback_order cancels/deletes non-completed bookings. CVSS 9.1. Python check/exploit PoC — pocbit.org/pocs/cve-2026-93399
Create: 2026-09-25 07:53:19 +0000 UTC Push: 2026-09-25 07:53:21 +0000 UTC |
murrez/CVE-2026-89055
Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_submit with arbitrary Media Library attachment IDs in items[].media. Linked files are permanently deleted when the review comment is purged. Python check/exploit PoC (PoCbit catalog).
Create: 2026-09-25 07:49:00 +0000 UTC Push: 2026-09-25 07:49:23 +0000 UTC |
murrez/CVE-2026-14281
Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields → admin. Python check/exploit PoC (PoCbit).
Create: 2026-09-25 07:43:43 +0000 UTC Push: 2026-09-25 07:43:44 +0000 UTC |
InertFluid/cve-2026-61732-lab
Benign, self-contained reproduction of CVE-2026-61732 (Decepticon ChatML role-boundary forgery)
Create: 2026-09-25 06:47:40 +0000 UTC Push: 2026-09-25 06:47:44 +0000 UTC |
jvidhan/cve-2026-43687
Create: 2026-09-25 06:06:52 +0000 UTC Push: 2026-09-25 06:06:53 +0000 UTC |
murrez/CVE-2026-48842
Roundcube virtuser_query pre-auth SQLi (CVE-2026-48842). Python PoC — version detect, virtuser plugin, login probe. https://pocbit.org
Create: 2026-09-25 05:59:39 +0000 UTC Push: 2026-09-25 05:59:40 +0000 UTC |
pocbit/CVE-2026-48842
Roundcube virtuser_query pre-auth SQLi (CVE-2026-48842). Python PoC — version detect, virtuser plugin, login probe. https://pocbit.org
Create: 2026-09-25 05:59:18 +0000 UTC Push: 2026-09-25 06:00:18 +0000 UTC |
HORKimhab/CVE-2025-9974
CVE-2025-9974 - Draft or TODO
Create: 2026-09-25 04:09:16 +0000 UTC Push: 2026-09-25 04:09:21 +0000 UTC |
HORKimhab/CVE-2026-65660
CVE-2026-65660 - Draft or TODO
Create: 2026-09-25 03:22:53 +0000 UTC Push: 2026-09-25 03:22:57 +0000 UTC |
AthBe1337/CVE-2026-43499-poc
Create: 2026-09-25 02:45:58 +0000 UTC Push: 2026-09-25 02:45:59 +0000 UTC |
joaovicdev/EXPLOIT-CVE-2026-87902
Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE condicional). Uso educacional/autorizado.
Create: 2026-09-25 01:06:33 +0000 UTC Push: 2026-09-25 01:06:37 +0000 UTC |
connorjaydunn/CVE-2026-79417
CVE-2026-79417 PoC
Create: 2026-09-25 00:57:35 +0000 UTC Push: 2026-09-25 00:58:45 +0000 UTC |
khellwan/CVE-2026-87902---PoC-
Proof of concept for vulnerability CVE-2026-87902 in Wordpress
Create: 2026-09-25 00:56:30 +0000 UTC Push: 2026-09-25 00:56:32 +0000 UTC |
khellwan/CVE-2026-87902_PoC
Proof of concept for vulnerability CVE-2026-87902 in Wordpress
Create: 2026-09-25 00:56:30 +0000 UTC Push: 2026-09-25 00:58:30 +0000 UTC |
diyiqiuye/CVE-2025-21479-FX5P
Temporary root for OPPO Find X5 Pro (PFEM00) via CVE-2025-21479 + KernelSU LKM late-load (cloud-buildable)
Create: 2026-09-24 23:20:42 +0000 UTC Push: 2026-09-24 23:20:48 +0000 UTC |
n-WN/cve-2024-0402-lab-assets
Create: 2026-09-24 21:51:14 +0000 UTC Push: 2026-09-24 21:51:20 +0000 UTC |
Previous
-181
-180
-179
-178
-177
-176
-175
-174
Next