unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
aramosf/CVE-2026-61500
CVE-2026-61500 Rejetto HFS predictable PRNG session forgery to RCE PoC and Docker lab
Create: 2026-09-26 15:23:41 +0000 UTC Push: 2026-09-26 15:23:46 +0000 UTC |
rwxrwxs/CVE-2026-87902
CVE-2026-87902
Create: 2026-09-26 15:15:55 +0000 UTC Push: 2026-09-26 15:15:56 +0000 UTC |
686f6c61/POC-WP-CORE-CVE-2026-93485
Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verificada, control 7.1.1 y la vía Post2Shell
Create: 2026-09-26 12:34:44 +0000 UTC Push: 2026-09-26 12:34:48 +0000 UTC |
qingle009/opace6-cve-2026-64560
OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address
Create: 2026-09-26 12:31:39 +0000 UTC Push: 2026-09-26 12:31:40 +0000 UTC |
murrez/CVE-2026-13249
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC
Create: 2026-09-26 11:59:53 +0000 UTC Push: 2026-09-26 11:59:54 +0000 UTC |
K3ysTr0K3R/CVE-2026-29053
Create: 2026-09-26 11:58:01 +0000 UTC Push: 2026-09-26 11:58:02 +0000 UTC |
0o176/CVE-2024-37054_PoC_HTB_SmartHire
MLFlow unsafe deserialization (CVE-2024-37054) written for HTB machine - SmartHire
Create: 2026-09-26 10:38:11 +0000 UTC Push: 2026-09-26 10:38:12 +0000 UTC |
NymiiTechTips/CVE-2025-48939
Create: 2026-09-26 09:43:41 +0000 UTC Push: 2026-09-26 09:43:42 +0000 UTC |
suominen/CVE-2026-93834
Create: 2026-09-26 09:42:45 +0000 UTC Push: 2026-09-26 09:42:46 +0000 UTC |
rahulreddykarne/CVE-2026-57836-Confluent_Kafka
Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka
Create: 2026-09-26 08:52:38 +0000 UTC Push: 2026-09-26 08:52:39 +0000 UTC |
rahulreddykarne/CVE-2026-65320-fastcore
Path Traversal (Tar Slip) in fastcore via untar_dir()
Create: 2026-09-26 08:29:03 +0000 UTC Push: 2026-09-26 08:29:05 +0000 UTC |
vvsy46/CVE-2016-5195-PoC
Create: 2026-09-26 08:10:11 +0000 UTC Push: 2026-09-26 08:10:12 +0000 UTC |
murrez/CVE-2026-18143
Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_file() with attacker-controlled .php filenames into web-accessible RFQ temp storage (popup quote flow required). CVSS 9.8. Python check/exploit PoC → pocbit.org/pocs/cve-2026-18143
Create: 2026-09-26 08:00:13 +0000 UTC Push: 2026-09-26 08:00:36 +0000 UTC |
langz337/CVE-2026-14281
CVE-2026-14281
Create: 2026-09-26 07:03:55 +0000 UTC Push: 2026-09-26 07:03:57 +0000 UTC |
petermalone/CVE-2026-43682
CVE-2026-43682: HFS+ B-tree kernel heap overflow in macOS
Create: 2026-09-26 05:47:11 +0000 UTC Push: 2026-09-26 05:47:14 +0000 UTC |
HackSpeak/CVE-2026-67279
MikroTrick (MikroTik RouterOS SSH takeover chain) PoC mirror - CVE-2026-67279 + CVE-2026-86060 (+67276); for authorized lab testing
Create: 2026-09-26 03:46:49 +0000 UTC Push: 2026-09-26 03:47:20 +0000 UTC |
abraxas/CVE-2026-15583
CVE-2026-15583 - Grafana MCP Server - High 8.6 - Unauthenticated POST /mcp - Unauthenticated Token Exfiltration (X-Grafana-URL Confused Deputy)
Create: 2026-09-26 03:34:02 +0000 UTC Push: 2026-09-26 03:34:11 +0000 UTC |
abraxas/CVE-2026-22599
CVE-2026-22599 - Strapi - Critical 9.3 - Authenticated POST /content-type-builder/content-types - Authenticated SQL Injection (Knex raw defaultTo)
Create: 2026-09-26 03:22:03 +0000 UTC Push: 2026-09-26 03:22:11 +0000 UTC |
abraxas/CVE-2026-52782
CVE-2026-52782 - OpenProject - Critical 9.9 - Authenticated PATCH /projects/{identifier}/settings/project_storages/{id} - Authenticated IDOR (Project Storage Folder Hijack)
Create: 2026-09-26 02:56:17 +0000 UTC Push: 2026-09-26 02:56:24 +0000 UTC |
abraxas/CVE-2026-48356
CVE-2026-48356 - Magento Open Source - Critical 9.3 - Unauthenticated POST /rest/default/V1/guest-carts/{cartId}/items - Unauthenticated Unrestricted File Upload (PolyShell)
Create: 2026-09-26 02:43:05 +0000 UTC Push: 2026-09-26 02:43:13 +0000 UTC |
Previous
-289
-288
-287
-286
-285
-284
-283
-282
Next