unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
0xBlackash/CVE-2026-43786
CVE-2026-43786
Create: 2026-09-26 21:28:39 +0000 UTC Push: 2026-09-26 21:28:41 +0000 UTC |
murrez/CVE-2026-82901
CVE-2026-82901 PoC: WordPress Ultra Addons for Contact Form 7 ≤3.5.50 unauth file upload via signature field when PDF Generator is enabled → wp-content/uploads/uacf7-uploads/. Fix: 3.5.51+. https://pocbit.org/pocs/cve-2026-82901
Create: 2026-09-26 21:11:27 +0000 UTC Push: 2026-09-26 21:11:28 +0000 UTC |
murrez/CVE-2026-97163
CVE-2026-97163 PoC: Joomla UP (lomart.fr) unauthenticated GitHub mini-install / remote action deployment (≤6.0.29). Detects plugin version, probes com_ajax install triggers. Fix: UP 6.1.0 / 5.2.1. https://pocbit.org/pocs/cve-2026-97163
Create: 2026-09-26 20:54:50 +0000 UTC Push: 2026-09-26 20:55:23 +0000 UTC |
murrez/CVE-2026-97161
CVE-2026-97161 PoC: Joomla UP (lomart.fr) unauthenticated path traversal / arbitrary file read via ajax-view (≤6.0.29). Fingerprints plugin, probes configuration.php. Fix: UP 6.1.0 / 5.2.1. https://pocbit.org/pocs/cve-2026-97161
Create: 2026-09-26 20:50:27 +0000 UTC Push: 2026-09-26 20:50:54 +0000 UTC |
murrez/CVE-2026-97160
CVE-2026-97160 PoC for Joomla UP (lomart.fr): privileged {up php=} shortcode eval code injection in versions 5.0.0–5.2.0 and 6.0.0–6.0.29 (fix 5.2.1 / 6.1.0). Detects plugin version and verifies public article execution.
Create: 2026-09-26 20:45:34 +0000 UTC Push: 2026-09-26 20:45:36 +0000 UTC |
qeize/cve-2026-97163-payload
CVE-2026-97163 PoC payload (UP plugin Joomla remote code installation)
Create: 2026-09-26 20:44:37 +0000 UTC Push: 2026-09-26 20:44:42 +0000 UTC |
murrez/CVE-2026-94132
AcyMailing Enterprise for Joomla < 11.1.0: POP3 mailbox actions save MIME attachments without extension checks to media/com_acym/upload/, enabling RCE when an attacker can email the monitored inbox (CVE-2026-94132, CVSS 9.5). Python check/exploit PoC —
Create: 2026-09-26 20:40:54 +0000 UTC Push: 2026-09-26 20:41:12 +0000 UTC |
murrez/CVE-2026-94130
Unauthenticated SQL injection in Joomla YouTube Gallery (joomlaboat.com, com_youtubegallery) ≤ 5.7.2 — video search/sort on the public yg_api endpoint. Python check/exploit PoC for CVE-2026-94130 — PoCbit.
Create: 2026-09-26 20:34:08 +0000 UTC Push: 2026-09-26 20:34:46 +0000 UTC |
langz337/CVE-2026-63030
Create: 2026-09-26 18:27:46 +0000 UTC Push: 2026-09-26 18:27:47 +0000 UTC |
raflesiait/CVE-2020-14008
CVE-2020-14008 - ManageEngine Applications Manager RCE
Create: 2026-09-26 18:02:58 +0000 UTC Push: 2026-09-26 18:02:59 +0000 UTC |
hitechcloud-vietnam/cve-2026-41940-PoC
A tool for exploiting CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0), allowing unauthenticated attackers to gain root-level WHM access by injecting CRLF sequences into server-side session files via the Authorization header — no credentials required.
Create: 2026-09-26 17:18:07 +0000 UTC Push: 2026-09-26 17:19:44 +0000 UTC |
1posix/CVE-2026-41089-POC
CVE-2026-41089 LongLogon: pre-auth CLDAP (UDP/389) stack buffer overflow crasher for unpatched Windows Server 2025 Netlogon (lsass 0xc0000409). Stdlib-only Python PoC + lab write-up.
Create: 2026-09-26 16:16:08 +0000 UTC Push: 2026-09-26 16:16:09 +0000 UTC |
linusboz12345-sys/cve-2020-0796-scanner
Create: 2026-09-26 16:05:34 +0000 UTC Push: 2026-09-26 16:05:35 +0000 UTC |
aramosf/CVE-2026-61500
CVE-2026-61500 Rejetto HFS predictable PRNG session forgery to RCE PoC and Docker lab
Create: 2026-09-26 15:23:41 +0000 UTC Push: 2026-09-26 15:23:46 +0000 UTC |
rwxrwxs/CVE-2026-87902
CVE-2026-87902
Create: 2026-09-26 15:15:55 +0000 UTC Push: 2026-09-26 15:15:56 +0000 UTC |
686f6c61/POC-WP-CORE-CVE-2026-93485
Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verificada, control 7.1.1 y la vía Post2Shell
Create: 2026-09-26 12:34:44 +0000 UTC Push: 2026-09-26 12:34:48 +0000 UTC |
qingle009/opace6-cve-2026-64560
OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address
Create: 2026-09-26 12:31:39 +0000 UTC Push: 2026-09-26 12:31:40 +0000 UTC |
murrez/CVE-2026-13249
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC
Create: 2026-09-26 11:59:53 +0000 UTC Push: 2026-09-26 11:59:54 +0000 UTC |
K3ysTr0K3R/CVE-2026-29053
Create: 2026-09-26 11:58:01 +0000 UTC Push: 2026-09-26 11:58:02 +0000 UTC |
0o176/CVE-2024-37054_PoC_HTB_SmartHire
MLFlow unsafe deserialization (CVE-2024-37054) written for HTB machine - SmartHire
Create: 2026-09-26 10:38:11 +0000 UTC Push: 2026-09-26 10:38:12 +0000 UTC |
Previous
-387
-386
-385
-384
-383
-382
-381
-380
Next