unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
murrez/CVE-2026-13249
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC
Create: 2026-09-26 11:59:53 +0000 UTC Push: 2026-09-26 11:59:54 +0000 UTC |
K3ysTr0K3R/CVE-2026-29053
Create: 2026-09-26 11:58:01 +0000 UTC Push: 2026-09-26 11:58:02 +0000 UTC |
0o176/CVE-2024-37054_PoC_HTB_SmartHire
MLFlow unsafe deserialization (CVE-2024-37054) written for HTB machine - SmartHire
Create: 2026-09-26 10:38:11 +0000 UTC Push: 2026-09-26 10:38:12 +0000 UTC |
NymiiTechTips/CVE-2025-48939
Create: 2026-09-26 09:43:41 +0000 UTC Push: 2026-09-26 09:43:42 +0000 UTC |
suominen/CVE-2026-93834
Create: 2026-09-26 09:42:45 +0000 UTC Push: 2026-09-26 09:42:46 +0000 UTC |
rahulreddykarne/CVE-2026-57836-Confluent_Kafka
Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka
Create: 2026-09-26 08:52:38 +0000 UTC Push: 2026-09-26 08:52:39 +0000 UTC |
rahulreddykarne/CVE-2026-65320-fastcore
Path Traversal (Tar Slip) in fastcore via untar_dir()
Create: 2026-09-26 08:29:03 +0000 UTC Push: 2026-09-26 08:29:05 +0000 UTC |
vvsy46/CVE-2016-5195-PoC
Create: 2026-09-26 08:10:11 +0000 UTC Push: 2026-09-26 08:10:12 +0000 UTC |
murrez/CVE-2026-18143
Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_file() with attacker-controlled .php filenames into web-accessible RFQ temp storage (popup quote flow required). CVSS 9.8. Python check/exploit PoC → pocbit.org/pocs/cve-2026-18143
Create: 2026-09-26 08:00:13 +0000 UTC Push: 2026-09-26 08:00:36 +0000 UTC |
langz337/CVE-2026-14281
CVE-2026-14281
Create: 2026-09-26 07:03:55 +0000 UTC Push: 2026-09-26 07:03:57 +0000 UTC |
petermalone/CVE-2026-43682
CVE-2026-43682: HFS+ B-tree kernel heap overflow in macOS
Create: 2026-09-26 05:47:11 +0000 UTC Push: 2026-09-26 05:47:14 +0000 UTC |
HackSpeak/CVE-2026-67279
MikroTrick (MikroTik RouterOS SSH takeover chain) PoC mirror - CVE-2026-67279 + CVE-2026-86060 (+67276); for authorized lab testing
Create: 2026-09-26 03:46:49 +0000 UTC Push: 2026-09-26 03:47:20 +0000 UTC |
abraxas/CVE-2026-15583
CVE-2026-15583 - Grafana MCP Server - High 8.6 - Unauthenticated POST /mcp - Unauthenticated Token Exfiltration (X-Grafana-URL Confused Deputy)
Create: 2026-09-26 03:34:02 +0000 UTC Push: 2026-09-26 03:34:11 +0000 UTC |
abraxas/CVE-2026-22599
CVE-2026-22599 - Strapi - Critical 9.3 - Authenticated POST /content-type-builder/content-types - Authenticated SQL Injection (Knex raw defaultTo)
Create: 2026-09-26 03:22:03 +0000 UTC Push: 2026-09-26 03:22:11 +0000 UTC |
abraxas/CVE-2026-52782
CVE-2026-52782 - OpenProject - Critical 9.9 - Authenticated PATCH /projects/{identifier}/settings/project_storages/{id} - Authenticated IDOR (Project Storage Folder Hijack)
Create: 2026-09-26 02:56:17 +0000 UTC Push: 2026-09-26 02:56:24 +0000 UTC |
abraxas/CVE-2026-48356
CVE-2026-48356 - Magento Open Source - Critical 9.3 - Unauthenticated POST /rest/default/V1/guest-carts/{cartId}/items - Unauthenticated Unrestricted File Upload (PolyShell)
Create: 2026-09-26 02:43:05 +0000 UTC Push: 2026-09-26 02:43:13 +0000 UTC |
Jake-Allmark/ThreatIntel
Hello, I built ThreatIntel because manually checking 20+ cyber feeds sounded miserable. It collects, correlates and prioritises threats, enriches CVEs with NVD/CISA KEV, checks customer-tech relevance, uses AI for analysis and threat hunts, then spits out a PDF. Press button. Cyber nonsense gets sorted.
Create: 2026-09-26 02:34:13 +0000 UTC Push: 2026-09-26 02:34:14 +0000 UTC |
abraxas/CVE-2026-75650
CVE-2026-75650 - Magento Open Source - Critical 10.0 - Unauthenticated POST /graphql - Unauthenticated Remote Code Execution (StyleSmuggler SSTI)
Create: 2026-09-26 02:32:55 +0000 UTC Push: 2026-09-26 02:33:04 +0000 UTC |
Farih123/CVE-2026-90817
Create: 2026-09-26 01:27:59 +0000 UTC Push: 2026-09-26 01:28:00 +0000 UTC |
abraxas/CVE-2026-96512
CVE-2026-96512 - sudo - High 7.8 - Authenticated LOCAL TZ=UTC+14 sudo -n /usr/bin/id - Local Privilege Escalation via Time-Window Bypass
Create: 2026-09-25 22:12:27 +0000 UTC Push: 2026-09-25 22:12:38 +0000 UTC |
Previous
-264
-263
-262
-261
-260
-259
-258
-257
Next