unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Boreas37/CVE-2026-73678-PoC
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
Create: 2026-08-16 14:05:05 +0000 UTC Push: 2026-08-16 14:05:09 +0000 UTC |
Franc-Zar/CVE-2026-72898-safe-detection
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
Create: 2026-08-16 12:55:07 +0000 UTC Push: 2026-08-16 12:55:08 +0000 UTC |
CuteeCat/CVE-2026-73633
CVE-2026-73633(S2-072)概念验证代码
Create: 2026-08-16 11:30:03 +0000 UTC Push: 2026-08-16 11:30:04 +0000 UTC |
Alixploit22/CVE-2025-11740
Create: 2026-08-16 09:49:50 +0000 UTC Push: 2026-08-16 09:49:51 +0000 UTC |
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
Create: 2026-08-16 09:11:25 +0000 UTC Push: 2026-08-16 09:11:58 +0000 UTC |
iamrajkumar1995/cve-2025-5781_FreePBX
In August 2025, a critical vulnerability was disclosed in the FreePBX Endpoint module. CVE-2025–57819 allows an unauthenticated attacker to exploit SQL injection in the Endpoint module and, through a chain of database manipulation and scheduled task execution, achieve remote code execution.
Create: 2026-08-16 08:53:38 +0000 UTC Push: 2026-08-16 08:53:39 +0000 UTC |
YonLiud/CVE-2026-76904
Unauthenticated SQL injection to complete RCE
Create: 2026-08-16 08:11:26 +0000 UTC Push: 2026-08-22 20:10:52 +0000 UTC |
uname1able/CVE-2022-24481-analysis
Create: 2026-08-16 06:06:27 +0000 UTC Push: 2026-08-16 06:06:31 +0000 UTC |
squeeze440/CVE-2026-73847-emlog-PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
Create: 2026-08-16 04:38:17 +0000 UTC Push: 2026-08-16 04:38:20 +0000 UTC |
squeeze440/CVE-2026-73519-WolfStack-PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
Create: 2026-08-16 04:38:09 +0000 UTC Push: 2026-08-16 04:38:13 +0000 UTC |
r2qa/CVE-2026-17544
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
Create: 2026-08-15 22:15:43 +0000 UTC Push: 2026-08-15 22:22:51 +0000 UTC |
SaiTeja-Erukude/CVE-2026-9147-uproot-rce
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
Create: 2026-08-15 21:58:32 +0000 UTC Push: 2026-08-15 21:58:33 +0000 UTC |
SaiTeja-Erukude/CVE-2026-47103-python-statemachine-rce
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
Create: 2026-08-15 21:25:54 +0000 UTC Push: 2026-08-15 21:25:55 +0000 UTC |
opaxial/CVE-2026-9830
CVE-2026-9830 Proof of Concept
Create: 2026-08-15 20:57:13 +0000 UTC Push: 2026-08-15 20:57:14 +0000 UTC |
SaiTeja-Erukude/CVE-2026-47117-openmed-rce
OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True
Create: 2026-08-15 20:23:48 +0000 UTC Push: 2026-08-15 20:23:49 +0000 UTC |
nicoibarburu/CVE-2021-4034
This is my simple implementation of an exploit for the PwnKit vulnerability.
Create: 2026-08-15 19:42:46 +0000 UTC Push: 2026-08-15 19:42:46 +0000 UTC |
judgedbykira/CVE-2026-20896-Gitea-Authentication-Bypass
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.
Create: 2026-08-15 19:01:05 +0000 UTC Push: 2026-08-15 19:01:06 +0000 UTC |
ForbiddenGarden/CVE-2024-999999-poc
Research artifact (fictitious CVE): symlink + prompt-injection canary used to test Stockpiler MCP server, see RESEARCH_NOTICE.md
Create: 2026-08-15 18:48:45 +0000 UTC Push: 2026-08-15 18:48:49 +0000 UTC |
vxssroott/CVE-2026-78906-ChatGPT-Prompt-Injection
KREMLIN — AI Infrastructure Vulnerability Research. CVE-2026-78906: Prompt injection and memory exfiltration in OpenAI's ChatGPT API.
Create: 2026-08-15 18:05:55 +0000 UTC Push: 2026-08-30 22:18:13 +0000 UTC |
0xTerror/CVE-2023-22047-Oracle-PeopleSoft-LFI
CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit allows an attacker to read arbitrary files from the target server without any authentication.
Create: 2026-08-15 17:22:45 +0000 UTC Push: 2026-08-15 17:22:46 +0000 UTC |
Previous
51
52
53
54
55
56
57
58
Next