unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
getdrive/wso2_cve-2026-5430_lab
Уязвимая лаборатория WSO2 API Manager 4.5.0 в Docker, сканер и эксплойт для CVE-2026-5430 (обход аутентификации через поддельный HS256 JWT)
Create: 2026-10-08 09:28:12 +0000 UTC Push: 2026-10-08 09:40:28 +0000 UTC |
hardeep-sudo/Keycloak-CVE-2026-18963-Exploit
Create: 2026-10-08 09:25:45 +0000 UTC Push: 2026-10-08 09:25:47 +0000 UTC |
SonOfABot/-CVE-2026-18963-POC
PoC for keycloak 1.26 vulnerability
Create: 2026-10-08 08:50:26 +0000 UTC Push: 2026-10-08 08:50:28 +0000 UTC |
kaizoku73/CVE-2026-31857-PoC
Proof of Concept for CVE-2026-31857, an authenticated Remote Code Execution vulnerability in Craft CMS caused by unsafe processing of user-controlled Twig expressions.
Create: 2026-10-08 08:48:46 +0000 UTC Push: 2026-10-08 08:48:48 +0000 UTC |
murrez/CVE-2026-21589
CVE-2026-21589 — Atlassian DC pre-auth arbitrary file read (CVSS 4.0 9.3). PoCbit PoC: atlassian-plugins-webresource ..:: traversal on /download/resources/ for Jira, Confluence, Bitbucket. check + exploit (WEB-INF/web.xml, crowd.properties). Batch JSONL, hits.txt. Not RCE. https://pocbit.org/pocs/cve-2026-21589
Create: 2026-10-08 08:31:03 +0000 UTC Push: 2026-10-08 08:31:05 +0000 UTC |
andreassudo/CVEHarvest
Multi-CVE exploitation framework in C++20 for Windows offensive testing and research
Create: 2026-10-08 08:05:11 +0000 UTC Push: 2026-10-08 08:12:00 +0000 UTC |
rxsklife/CVE-2026-21589
CVE-2026-21589 is a critical (CVSS 9.3) arbitrary file access vulnerability affecting all versions of eight Atlassian Data Center products, including Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, Fisheye, and Jira Service Management.
Create: 2026-10-08 05:41:15 +0000 UTC Push: 2026-10-08 05:41:16 +0000 UTC |
rxsklife/CVE-2026-105192
CVE-2026-105192 is a critical (CVSS 9.8) vulnerability in LMCache, an open-source distributed key-value cache for LLM inference engines like vLLM.
Create: 2026-10-08 05:33:03 +0000 UTC Push: 2026-10-08 05:33:05 +0000 UTC |
theendofabbys/CVE-2026-61424
Create: 2026-10-08 03:49:51 +0000 UTC Push: 2026-10-08 03:49:52 +0000 UTC |
theendofabbys/CVE-2026-49049
Create: 2026-10-08 03:35:47 +0000 UTC Push: 2026-10-08 03:35:48 +0000 UTC |
theendofabbys/CVE-2026-56291
Create: 2026-10-08 03:31:32 +0000 UTC Push: 2026-10-08 03:32:15 +0000 UTC |
theendofabbys/CVE-2026-48907
Create: 2026-10-08 03:23:34 +0000 UTC Push: 2026-10-08 03:23:35 +0000 UTC |
HORKimhab/CVE-2026-Wordpress
CVE-2026-Wordpress
Create: 2026-10-08 02:00:12 +0000 UTC Push: 2026-10-08 02:00:17 +0000 UTC |
yuwkaaa/CVE-2026-107268
Drupal: miniorange_2fa
Create: 2026-10-08 01:01:40 +0000 UTC Push: 2026-10-08 01:01:41 +0000 UTC |
davidvrns/CVE-2026-5430-WSO2
Detection PoC for CVE-2026-5430 — unauthenticated JWT algorithm bypass (CVSS 10.0) affecting WSO2 API Manager 4.1.0–4.6.0. Read-only assessment tool with patch confirmation and WAF detection. Authorized use only.
Create: 2026-10-08 00:42:07 +0000 UTC Push: 2026-10-08 00:42:31 +0000 UTC |
QASIM1401/CVE-2025-58226-PoC
CVE-2025-58226 — 3D FlipBook <= 1.16.16 unauthenticated sensitive data exposure: two-stage PoC (enumerate -> leak file URLs -> download) + nuclei template
Create: 2026-10-07 23:46:42 +0000 UTC Push: 2026-10-07 23:46:54 +0000 UTC |
ntru0/CVE_2024_38063_homelab
Create: 2026-10-07 21:17:19 +0000 UTC Push: 2026-10-07 21:17:20 +0000 UTC |
Kolya080808/CVE-2026-97332
CVE-2026-97332 PoC (WordPress Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass)
Create: 2026-10-07 20:29:45 +0000 UTC Push: 2026-10-07 20:29:46 +0000 UTC |
Kolya080808/CVE-2026-97332-PoC
CVE-2026-97332 PoC (WordPress Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass)
Create: 2026-10-07 20:29:45 +0000 UTC Push: 2026-10-07 20:29:46 +0000 UTC |
murrez/CVE-2026-105844
CVE-2026-105844 — Payload CMS @payloadcms/plugin-import-export <3.88.0 unauth prototype pollution (CWE-1321, CVSS 4.0 9.3). PoCbit PoC: POST /api/exports/export-preview fields __proto__.overrideAccess → ACL bypass / data leak. check/exploit/mass. Fix 3.88.0+. https://pocbit.org/pocs/cve-2026-105844
Create: 2026-10-07 19:55:44 +0000 UTC Push: 2026-10-07 19:56:12 +0000 UTC |
Previous
-724
-723
-722
-721
-720
-719
-718
-717
Next