unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
be-keb/CVE-2026-12227-Visual-Composer-Website-Builder-Unauthenticated-Local-File-Inclusion-LFI-
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0, This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE).
Create: 2026-09-27 09:03:34 +0000 UTC Push: 2026-09-27 09:03:35 +0000 UTC |
be-keb/CVE-2026-12227
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0, This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE).
Create: 2026-09-27 09:03:34 +0000 UTC Push: 2026-09-27 09:09:06 +0000 UTC |
v4naxx/YellowKey-BitLocker-CVE-2026-45585
YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own. Extract and run. Official free download. Download:➧
Create: 2026-09-27 07:58:27 +0000 UTC Push: 2026-09-27 07:58:29 +0000 UTC |
YellowKeyBitLocker-CVE/YellowKey-BitLocker-CVE-2026-45585
YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own. Extract and run. Official free download. Download:➧
Create: 2026-09-27 07:58:27 +0000 UTC Push: 2026-09-27 08:30:58 +0000 UTC |
raflesiait/CVE-2020-14008---ManageEngine
CVE-2020-14008 — ManageEngine Applications Manager Remote Code Execution
Create: 2026-09-27 07:41:02 +0000 UTC Push: 2026-09-27 07:41:13 +0000 UTC |
techupdate24/citrix-netscaler-cve-2026-8452-rce
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.
Create: 2026-09-27 07:29:49 +0000 UTC Push: 2026-09-27 07:29:54 +0000 UTC |
4xura/CVE-2026-44011-craftcms-auth-rce
The PoC of CVE-2026-44011: Craft CMS, from 4.0.0 to before 4.17.12 and 5.9.18, contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server.
Create: 2026-09-27 06:57:34 +0000 UTC Push: 2026-09-27 06:57:35 +0000 UTC |
rahulreddykarne/CVE-2026-8712-Wyoming
CVE-2026-8712: Unauthenticated SSRF / Backend URI Override in Wyoming HTTP API via uri Query Parameter
Create: 2026-09-27 06:55:11 +0000 UTC Push: 2026-09-27 06:55:12 +0000 UTC |
murrez/CVE-2026-100740
CVE-2026-100740 PoC: D-Link DIR-895L A1_102b07 L2TP Host Name AVP out-of-bounds write in tunnel_set_params (UDP 1701). Device fingerprint + optional OOB trigger packet for authorized lab testing. https://pocbit.org/pocs/cve-2026-100740
Create: 2026-09-27 05:40:35 +0000 UTC Push: 2026-09-27 05:40:36 +0000 UTC |
rmhowe425/POC-CVE-2025-11201
Create: 2026-09-27 01:50:15 +0000 UTC Push: 2026-09-27 01:50:16 +0000 UTC |
osflaky/exp-logpresso-CVE-2021-44228-Scanner
snapshot of logpresso/CVE-2021-44228-Scanner at a pinned commit, for cross platform ci legs
Create: 2026-09-27 01:24:13 +0000 UTC Push: 2026-09-27 01:24:14 +0000 UTC |
Muskann02/cve-2021-44228-lab
Docker-based educational lab for CVE-2021-44228 (Log4Shell)
Create: 2026-09-26 22:25:22 +0000 UTC Push: 2026-09-26 22:25:26 +0000 UTC |
0xBlackash/CVE-2026-43786
CVE-2026-43786
Create: 2026-09-26 21:28:39 +0000 UTC Push: 2026-09-26 21:28:41 +0000 UTC |
murrez/CVE-2026-82901
CVE-2026-82901 PoC: WordPress Ultra Addons for Contact Form 7 ≤3.5.50 unauth file upload via signature field when PDF Generator is enabled → wp-content/uploads/uacf7-uploads/. Fix: 3.5.51+. https://pocbit.org/pocs/cve-2026-82901
Create: 2026-09-26 21:11:27 +0000 UTC Push: 2026-09-26 21:11:28 +0000 UTC |
murrez/CVE-2026-97163
CVE-2026-97163 PoC: Joomla UP (lomart.fr) unauthenticated GitHub mini-install / remote action deployment (≤6.0.29). Detects plugin version, probes com_ajax install triggers. Fix: UP 6.1.0 / 5.2.1. https://pocbit.org/pocs/cve-2026-97163
Create: 2026-09-26 20:54:50 +0000 UTC Push: 2026-09-26 20:55:23 +0000 UTC |
murrez/CVE-2026-97161
CVE-2026-97161 PoC: Joomla UP (lomart.fr) unauthenticated path traversal / arbitrary file read via ajax-view (≤6.0.29). Fingerprints plugin, probes configuration.php. Fix: UP 6.1.0 / 5.2.1. https://pocbit.org/pocs/cve-2026-97161
Create: 2026-09-26 20:50:27 +0000 UTC Push: 2026-09-26 20:50:54 +0000 UTC |
murrez/CVE-2026-97160
CVE-2026-97160 PoC for Joomla UP (lomart.fr): privileged {up php=} shortcode eval code injection in versions 5.0.0–5.2.0 and 6.0.0–6.0.29 (fix 5.2.1 / 6.1.0). Detects plugin version and verifies public article execution.
Create: 2026-09-26 20:45:34 +0000 UTC Push: 2026-09-26 20:45:36 +0000 UTC |
qeize/cve-2026-97163-payload
CVE-2026-97163 PoC payload (UP plugin Joomla remote code installation)
Create: 2026-09-26 20:44:37 +0000 UTC Push: 2026-09-26 20:44:42 +0000 UTC |
murrez/CVE-2026-94132
AcyMailing Enterprise for Joomla < 11.1.0: POP3 mailbox actions save MIME attachments without extension checks to media/com_acym/upload/, enabling RCE when an attacker can email the monitored inbox (CVE-2026-94132, CVSS 9.5). Python check/exploit PoC —
Create: 2026-09-26 20:40:54 +0000 UTC Push: 2026-09-26 20:41:12 +0000 UTC |
murrez/CVE-2026-94130
Unauthenticated SQL injection in Joomla YouTube Gallery (joomlaboat.com, com_youtubegallery) ≤ 5.7.2 — video search/sort on the public yg_api endpoint. Python check/exploit PoC for CVE-2026-94130 — PoCbit.
Create: 2026-09-26 20:34:08 +0000 UTC Push: 2026-09-26 20:34:46 +0000 UTC |
Previous
-406
-405
-404
-403
-402
-401
-400
-399
Next