unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
matesz44/cve-2026-39987
CVE-2026-39987 PoC: Marimo<0.23.0 Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Create: 2026-08-12 19:12:11 +0000 UTC Push: 2026-08-12 19:12:12 +0000 UTC |
Boreas37/CVE-2026-41452-PoC
CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5
Create: 2026-08-12 18:35:57 +0000 UTC Push: 2026-08-12 18:35:58 +0000 UTC |
Boreas37/CVE-2026-73034-PoC
CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff
Create: 2026-08-12 18:35:23 +0000 UTC Push: 2026-08-12 18:35:27 +0000 UTC |
Boreas37/CVE-2026-33267-PoC
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4
Create: 2026-08-12 17:18:32 +0000 UTC Push: 2026-08-12 17:18:33 +0000 UTC |
Boreas37/CVE-2026-17544-PoC
CVE-2026-17544 — PHP bcmath bccomp() OOB write (stack smashing). Verified: crash on 8.4.23/8.5.8, fixed in 8.4.24. GHSA-x692-q9x7-8c3f
Create: 2026-08-12 17:17:50 +0000 UTC Push: 2026-08-12 17:17:54 +0000 UTC |
686f6c61/POC-CopyEscape-CVE-2026-17106
PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.
Create: 2026-08-12 16:41:52 +0000 UTC Push: 2026-08-12 16:41:56 +0000 UTC |
guard-wait/CVE-2026-64563_EXP
关于CVE-2026-64563未完全验证的一种利用思路
Create: 2026-08-12 16:35:16 +0000 UTC Push: 2026-08-12 16:35:17 +0000 UTC |
yora1928/CVE-2026-48908-by-yora
Passive security checker for CVE-2026-48908 affecting SP Page Builder.
Create: 2026-08-12 16:12:13 +0000 UTC Push: 2026-08-12 16:12:13 +0000 UTC |
aramosf/CVE-2026-68398
CVE-2026-68398 Ubuntu PPPoL2TP use-after-free local privilege escalation
Create: 2026-08-12 15:04:01 +0000 UTC Push: 2026-08-12 15:26:02 +0000 UTC |
Gutierre0x80/CVE-2026-59827
Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code execution.
Create: 2026-08-12 14:34:15 +0000 UTC Push: 2026-08-12 14:34:16 +0000 UTC |
HORKimhab/CVE-2026-28956
CVE-2026-28956 - Draft or TODO
Create: 2026-08-12 14:23:48 +0000 UTC Push: 2026-08-12 14:24:28 +0000 UTC |
0xBlackash/CVE-2026-72898
CVE-2026-72898
Create: 2026-08-12 13:54:46 +0000 UTC Push: 2026-08-12 13:54:47 +0000 UTC |
Knz-source/CVE-2026-23111-POC-noddlenpottato
s
Create: 2026-08-12 13:23:42 +0000 UTC Push: 2026-08-12 13:23:43 +0000 UTC |
QM4RS/CVE-2026-0075
Create: 2026-08-12 13:09:06 +0000 UTC Push: 2026-08-12 13:09:11 +0000 UTC |
leoelsolh/CVE-2026-69263
MCP environment-variable blocklist bypass leads to unauthenticated RCE in Flowise 3.1.1
Create: 2026-08-12 12:20:22 +0000 UTC Push: 2026-08-12 12:20:23 +0000 UTC |
AC8999/CVE-2026-27344
Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through <= 1.0.5.
Create: 2026-08-12 12:06:09 +0000 UTC Push: 2026-08-12 12:06:10 +0000 UTC |
ZildanZ/CVE-2026-64638
Create: 2026-08-12 11:58:32 +0000 UTC Push: 2026-08-12 11:58:32 +0000 UTC |
Virgula0/CVE-2026-44402
Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1
Create: 2026-08-12 11:35:20 +0000 UTC Push: 2026-08-12 12:37:59 +0000 UTC |
heartlesseorg-dot/CVE-2024-52806-PoC
Create: 2026-08-12 10:39:38 +0000 UTC Push: 2026-08-12 10:40:25 +0000 UTC |
Leeyoonjoo/CVE-2026-42533
Create: 2026-08-12 09:48:05 +0000 UTC Push: 2026-08-17 10:30:28 +0000 UTC |
Previous
56
57
58
59
60
61
62
63
Next