unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Boreas37/CVE-2026-88008-PoC
CVE-2026-88008 - Traefik (<=2.11.56 / <=3.7.12): a client-controlled h2c upgrade tunnels past routers and middleware (BasicAuth/ForwardAuth/IPAllowList), unauthorised access + no access logging. Stdlib-only Python PoC + real Jetty h2c lab, verified on v3.7.12 vs v3.7.13.
Create: 2026-09-27 22:58:31 +0000 UTC Push: 2026-09-27 22:58:38 +0000 UTC |
gdfurr98/ply-cve-2025-56005-lab
Lab demonstrating that CVE-2025-56005 is real and does allow arbitrary code execution at a minimum (the debate about RCE notwithstanding here), and shows that ply-safepickle does block the exploit path.
Create: 2026-09-27 22:49:37 +0000 UTC Push: 2026-09-27 22:49:38 +0000 UTC |
Boreas37/CVE-2026-71963-PoC
CVE-2026-71963 - Hermes Agent 0.18.2-0.21.0 RCE via a repository-delivered .git/config (core.fsmonitor). Stdlib-only Python, verified on real 0.21.0 with a clean negative control on the fixed build.
Create: 2026-09-27 22:31:47 +0000 UTC Push: 2026-09-27 22:31:55 +0000 UTC |
khush-613/CVE-2026-44011-poc
Create: 2026-09-27 22:01:43 +0000 UTC Push: 2026-09-27 22:01:44 +0000 UTC |
ImperfectP/CVE-2026-600004
Functional script
Create: 2026-09-27 21:50:13 +0000 UTC Push: 2026-09-27 21:50:14 +0000 UTC |
khush-613/CVE-2026-34990-poc
Create: 2026-09-27 21:38:26 +0000 UTC Push: 2026-09-27 21:38:27 +0000 UTC |
Cyberuser-hash/CVE-2026-44011-craft-rce-poc
CVE-2026-44011-craft-rce-poc
Create: 2026-09-27 20:37:21 +0000 UTC Push: 2026-09-27 20:37:23 +0000 UTC |
murrez/CVE-2026-88772
CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS probe. CTX697096; active exploitation reported. https://pocbit.org/pocs/cve-2026-88772
Create: 2026-09-27 20:24:56 +0000 UTC Push: 2026-09-27 20:24:58 +0000 UTC |
hacbs-release-tests/collectors-no-cve-e173c20d
Create: 2026-09-27 20:24:02 +0000 UTC Push: 2026-09-27 20:25:02 +0000 UTC |
Maalfer/CVE-2026-87902-exploit
Exploit para explotar la vulnerabilidad CVE-2026-87902 que se acontece en el core de WordPress
Create: 2026-09-27 20:18:56 +0000 UTC Push: 2026-09-27 20:18:57 +0000 UTC |
predyy/CVE-2026-34990
CVE-2026-34990 minimal PoC. CUPS <= 2.4.16 local privesc.
Create: 2026-09-27 19:41:06 +0000 UTC Push: 2026-09-27 19:41:07 +0000 UTC |
DENNISDGR/CVE-2026-44011-poc
Authenticated Craft CMS RCE PoC for CVE-2026-44011
Create: 2026-09-27 19:02:15 +0000 UTC Push: 2026-09-27 19:02:16 +0000 UTC |
abatsakidis/CVE-2026-14281-check
A Windows-friendly, non-destructive Python checker for detecting WordPress installations potentially affected by CVE-2026-14281.
Create: 2026-09-27 18:30:10 +0000 UTC Push: 2026-09-27 18:30:29 +0000 UTC |
DENNISDGR/CVE-2026-34990-poc
Local privilege escalation PoC for CVE-2026-34990 using a CUPS root file write vulnerability.
Create: 2026-09-27 18:24:03 +0000 UTC Push: 2026-09-27 18:24:04 +0000 UTC |
abatsakidis/wp-cve-2026-87902-checker
Defensive WordPress security scanner for CVE-2026-87902 — local filesystem inspection and safe remote HTTP/HTTPS assessment.
Create: 2026-09-27 18:20:57 +0000 UTC Push: 2026-09-27 18:20:58 +0000 UTC |
predyy/CVE-2026-28695
CVE-2026-28695 PoC - Authenticated blind remote code execution in Craft CMS.
Create: 2026-09-27 18:15:52 +0000 UTC Push: 2026-09-27 18:15:53 +0000 UTC |
khanna419/cve-2021-43798-lab
Create: 2026-09-27 17:57:29 +0000 UTC Push: 2026-09-27 17:57:30 +0000 UTC |
H4zaz/CVE-2026-76547
PHP Object Injection in Profile Builder < 4.0.1
Create: 2026-09-27 16:16:18 +0000 UTC Push: 2026-09-27 16:16:19 +0000 UTC |
nth347/mediawiki-CVE-2026-100382
Create: 2026-09-27 15:31:44 +0000 UTC Push: 2026-09-27 15:52:43 +0000 UTC |
tls456/CVE-2026-43805-PoC
CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept
Create: 2026-09-27 14:47:40 +0000 UTC Push: 2026-09-27 14:47:45 +0000 UTC |
Previous
-428
-427
-426
-425
-424
-423
-422
-421
Next