unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
abraxas/CVE-2026-5430
CVE-2026-5430 - WSO2 API Manager - Critical 10.0 - Unauthenticated GET /api/am/admin/v4/tenant-config - Unauthenticated Account Takeover (JWT Algorithm Bypass)
Create: 2026-09-25 20:53:51 +0000 UTC Push: 2026-09-25 20:54:05 +0000 UTC |
ShadowForge-Cyber/CVE-2026-65660-Poc
Malicious Register Directive Code Injection Exploit
Create: 2026-09-25 20:27:27 +0000 UTC Push: 2026-09-25 20:27:29 +0000 UTC |
SVTagan/WP-CVE-2026-87902
WordPress CVE-2026-87902 diagnostic check
Create: 2026-09-25 19:22:36 +0000 UTC Push: 2026-09-25 19:22:37 +0000 UTC |
redhat-tssc-tmm/CVE-2024-3651-exploit
Simple app to demonstrate CVE-2024-3651
Create: 2026-09-25 18:39:49 +0000 UTC Push: 2026-09-25 18:57:06 +0000 UTC |
Ermensonx/sudotimewarp-cve-2026-96512-
Create: 2026-09-25 18:17:19 +0000 UTC Push: 2026-09-25 18:17:20 +0000 UTC |
ChinaRan0/CVE-2026-59310-POC
CVE-2026-59310-POC 仅用于自测,请勿用于攻击
Create: 2026-09-25 16:05:26 +0000 UTC Push: 2026-09-25 16:05:27 +0000 UTC |
mohamedbrek/SOC336-CVE-2025-21298-Investigation
LetsDefend SOC lab investigating CVE-2025-21298 Windows OLE Zero-Click RCE exploitation.
Create: 2026-09-25 16:02:10 +0000 UTC Push: 2026-09-25 16:02:15 +0000 UTC |
gagaltotal/CVE-2026-mikrotik-poc
CVE-2026-86060 - CVE-2026-67279 - CVE-2026-67276 RouterOS SSH
Create: 2026-09-25 15:59:34 +0000 UTC Push: 2026-09-25 15:59:35 +0000 UTC |
hacbs-release-tests/collectors-no-cve-20c936c7
Create: 2026-09-25 15:38:47 +0000 UTC Push: 2026-09-25 15:38:51 +0000 UTC |
RELIHR/CVE-2026-43499
a-16 kernel in
Create: 2026-09-25 15:37:58 +0000 UTC Push: 2026-09-25 15:38:41 +0000 UTC |
rushikesh-a-bhujbal/CVE-2007-2447
Samba 3.0.20 username map script command injection exploit — reverse shell via SMB authentication, built from scratch in Python using impacket. No Metasploit.
Create: 2026-09-25 15:35:48 +0000 UTC Push: 2026-09-25 15:35:49 +0000 UTC |
Wangs-official/opace6-cve-2026-64560
针对 OnePlus Ace6 设备的 cve-2026-64560 复现
Create: 2026-09-25 13:42:42 +0000 UTC Push: 2026-09-25 13:42:44 +0000 UTC |
hacbs-release-tests/collectors-no-cve-206e0163
Create: 2026-09-25 13:41:32 +0000 UTC Push: 2026-09-25 13:41:36 +0000 UTC |
Become-ILLUSORY/cve-2026-64560-a16
CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port
Create: 2026-09-25 13:23:40 +0000 UTC Push: 2026-09-25 14:39:24 +0000 UTC |
pentagon404uzb/CVE-2021-1675-Local-Privilege-Escalation-CVSS-7.8-
Create: 2026-09-25 12:04:55 +0000 UTC Push: 2026-09-25 12:04:56 +0000 UTC |
hacbs-release-tests/collectors-no-cve-81a1b206
Create: 2026-09-25 11:53:50 +0000 UTC Push: 2026-09-25 11:53:55 +0000 UTC |
AtlasVector/Kestra-cve-2026-53576
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common Docker-socket misconfiguration turns container-root into full host compromise.
Create: 2026-09-25 10:21:00 +0000 UTC Push: 2026-09-25 10:21:01 +0000 UTC |
roshanrajbanshi/cve-2023-25690-smuggler
Python exploit for CVE-2023-25690 — Apache HTTP Request Smuggling via CRLF injection in mod_rewrite/mod_proxy. Built and tested against TryHackMe's Contrabando box.
Create: 2026-09-25 09:23:01 +0000 UTC Push: 2026-09-25 09:23:02 +0000 UTC |
murrez/CVE-2026-93399
Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointments; bookly_rollback_order cancels/deletes non-completed bookings. CVSS 9.1. Python check/exploit PoC — pocbit.org/pocs/cve-2026-93399
Create: 2026-09-25 07:53:19 +0000 UTC Push: 2026-09-25 07:53:21 +0000 UTC |
murrez/CVE-2026-89055
Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_submit with arbitrary Media Library attachment IDs in items[].media. Linked files are permanently deleted when the review comment is purged. Python check/exploit PoC (PoCbit catalog).
Create: 2026-09-25 07:49:00 +0000 UTC Push: 2026-09-25 07:49:23 +0000 UTC |
Previous
-222
-221
-220
-219
-218
-217
-216
-215
Next