unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
krl5/CVE-2026-41875-EXPLOIT-QuickCart-one-click-Account-Takeover
Create: 2026-10-05 13:57:12 +0000 UTC Push: 2026-10-05 13:57:14 +0000 UTC |
hghgr69/CVE-2026-41875-EXPLOIT-QuickCart-one-click-Account-Takeover
Create: 2026-10-05 13:57:12 +0000 UTC Push: 2026-10-05 13:59:25 +0000 UTC |
kashishtopi/CVE-2026-105314
Create: 2026-10-05 13:20:07 +0000 UTC Push: 2026-10-05 13:20:13 +0000 UTC |
RayanAlmulhim/CVE-2026-105134-lab
Educational lab and clean-room reproduction demonstrating the OS command injection pattern in CVE-2026-105134. For defensive research only.
Create: 2026-10-05 13:00:51 +0000 UTC Push: 2026-10-05 13:09:45 +0000 UTC |
0xBlackash/CVE-2026-86950
CVE-2026-86950
Create: 2026-10-05 12:32:14 +0000 UTC Push: 2026-10-05 12:32:16 +0000 UTC |
tunahantekeoglu/CVE-2025-54769
Create: 2026-10-05 10:09:13 +0000 UTC Push: 2026-10-05 10:09:15 +0000 UTC |
dr4mohamed/CVE-2026-46333
Create: 2026-10-05 09:42:52 +0000 UTC Push: 2026-10-05 09:43:29 +0000 UTC |
0xSemizzz/CVE-2026-95622
ModemManager denial-of-service vulnerability caused by an assertion failure when processing a specially crafted Cell Broadcast Message (CBM).
Create: 2026-10-05 08:11:15 +0000 UTC Push: 2026-10-05 08:11:16 +0000 UTC |
weae26/cve-2024-4367-poc
CVE-2024-4367 PDF.js FontMatrix injection PoC (payload: alert(1)) - authorized pentest artifact
Create: 2026-10-05 05:36:42 +0000 UTC Push: 2026-10-05 05:36:54 +0000 UTC |
Vijishanmugavel/metasploitable2-vsftpd-cve-2011-2523
Controlled vulnerability assessment of Metasploitable 2, identifying and validating CVE-2011-2523 in vsftpd 2.3.4 within an isolated lab environment.
Create: 2026-10-05 03:33:16 +0000 UTC Push: 2026-10-05 03:33:18 +0000 UTC |
0xcrypto/CVE-2026-86881
Analysis of CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Create: 2026-10-05 02:31:05 +0000 UTC Push: 2026-10-05 02:31:07 +0000 UTC |
rabakuku/CVE-2026-40281
A Working PoC For CVE-2026-40281
Create: 2026-10-05 00:34:41 +0000 UTC Push: 2026-10-05 00:34:43 +0000 UTC |
MRdark-ops/exploit-scanner-CVE-2026-14378
Proof-of-concept scanner and exploit helper for **CVE-2026-14378**: unauthenticated **administrator session takeover** in the WordPress plugin **DevKit Pro** (dplugins) through a flawed user-switch “revert” flow.
Create: 2026-10-04 20:08:03 +0000 UTC Push: 2026-10-04 20:08:04 +0000 UTC |
gotr00t0day/CVE-2022-40684
A critical authentication bypass vulnerability in Fortinet products (FortiOS, FortiProxy, and FortiSwitchManager)
Create: 2026-10-04 18:15:27 +0000 UTC Push: 2026-10-04 18:15:29 +0000 UTC |
K52-ai/CVE-2026-83627
CVE-2026-83627 — Hummingbird Performance <= 3.21.0 Unauthenticated RCE. Pure Python exploit. by K52-ai.
Create: 2026-10-04 17:25:32 +0000 UTC Push: 2026-10-04 17:25:33 +0000 UTC |
sifatnotes/-Recon-MySQL-SSH-ICA-CVE-2026-13247-Tomcat
Hands-on cybersecurity and CTF labs covering service fingerprinting, MySQL enumeration, HTTP clues, SSH discovery, port probing, host discovery, ICA access paths, CVE-2026-13247 WordPress Stored XSS, Thales, and Tomcat security.
Create: 2026-10-04 17:20:11 +0000 UTC Push: 2026-10-04 17:20:13 +0000 UTC |
K52-ai/CVE-2018-7600
CVE-2018-7600 (Drupalgeddon2) — Drupal RCE exploit tool. Standalone Python PoC for authorized security testing. CVSS 9.8 Critical. by K52-ai.
Create: 2026-10-04 17:04:22 +0000 UTC Push: 2026-10-04 17:04:24 +0000 UTC |
Hassham1/CVE-2026-103355-unlimited-elements-sqli-poc
CVE-2026-103355 - Unlimited Elements For Elementor <= 2.0.20 unauthenticated blind SQL injection via terms-listing identifiers (CVSS 9.3): Docker validation lab with vulnerable (2.0.20) vs patched (2.0.21) controls, read-only boolean-oracle PoC, nuclei version screen. Authorized security research only.
Create: 2026-10-04 14:29:23 +0000 UTC Push: 2026-10-04 14:29:34 +0000 UTC |
wvllxe/CVE-2026-104991
CVE-2026-104991 — Missing Authorization (BOLA/IDOR) in Phproject REST API read/comment endpoints
Create: 2026-10-04 13:23:39 +0000 UTC Push: 2026-10-04 13:23:44 +0000 UTC |
Nxploited/CVE-2026-96451
WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
Create: 2026-10-04 12:50:53 +0000 UTC Push: 2026-10-04 12:50:55 +0000 UTC |
Previous
-636
-635
-634
-633
-632
-631
-630
-629
Next