unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
abatsakidis/CVE-2026-14281-check
A Windows-friendly, non-destructive Python checker for detecting WordPress installations potentially affected by CVE-2026-14281.
Create: 2026-09-27 18:30:10 +0000 UTC Push: 2026-09-27 18:30:29 +0000 UTC |
DENNISDGR/CVE-2026-34990-poc
Local privilege escalation PoC for CVE-2026-34990 using a CUPS root file write vulnerability.
Create: 2026-09-27 18:24:03 +0000 UTC Push: 2026-09-27 18:24:04 +0000 UTC |
abatsakidis/wp-cve-2026-87902-checker
Defensive WordPress security scanner for CVE-2026-87902 — local filesystem inspection and safe remote HTTP/HTTPS assessment.
Create: 2026-09-27 18:20:57 +0000 UTC Push: 2026-09-27 18:20:58 +0000 UTC |
predyy/CVE-2026-28695
CVE-2026-28695 PoC - Authenticated blind remote code execution in Craft CMS.
Create: 2026-09-27 18:15:52 +0000 UTC Push: 2026-09-27 18:15:53 +0000 UTC |
khanna419/cve-2021-43798-lab
Create: 2026-09-27 17:57:29 +0000 UTC Push: 2026-09-27 17:57:30 +0000 UTC |
H4zaz/CVE-2026-76547
PHP Object Injection in Profile Builder < 4.0.1
Create: 2026-09-27 16:16:18 +0000 UTC Push: 2026-09-27 16:16:19 +0000 UTC |
nth347/mediawiki-CVE-2026-100382
Create: 2026-09-27 15:31:44 +0000 UTC Push: 2026-09-27 15:52:43 +0000 UTC |
tls456/CVE-2026-43805-PoC
CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept
Create: 2026-09-27 14:47:40 +0000 UTC Push: 2026-09-27 14:47:45 +0000 UTC |
Alexandertanay/jenkins-cve-2024-23897-lab
Create: 2026-09-27 14:35:19 +0000 UTC Push: 2026-09-27 14:35:20 +0000 UTC |
jed-parsec/CVE-2026-63030-60137-wp2shell-lab
Unauthenticated SQL injection PoC and vulnerable lab environment for WP2Shell (CVE-2026-63030 + CVE-2026-60137) — a WordPress REST API batch route confusion chained into a WP_Query SQL injection. Includes Docker Compose lab setup and a Python exploitation script. For authorized security research only.
Create: 2026-09-27 13:25:52 +0000 UTC Push: 2026-09-27 13:25:53 +0000 UTC |
tc4dy/CVE-2026-67279-86060-Toolkit
🛡️ CVE-2026-67279 + CVE-2026-86060 – MikroTrick MikroTik RouterOS SSH Pre-Auth Takeover (CVSS 9.2) | Red/Blue Team suite. 2 tools: Full Exploit (rekey bypass, fd-2 policy swap, full-admin shell, plant, mass scan, SOCKS5/Tor, stealth) & SafeDetect (banner/version audit, IoC guidance, JSON/CSV/HTML). Use Ethically & Safety only.
Create: 2026-09-27 12:03:42 +0000 UTC Push: 2026-09-27 12:04:23 +0000 UTC |
langz337/CVE-2026-87902
Unauthenticated LFI and conditional RCE scanner for CVE-2026-87902 in WordPress Core (4.7.0 – 7.1.1).
Create: 2026-09-27 12:03:13 +0000 UTC Push: 2026-09-27 12:03:15 +0000 UTC |
4minx/CVE-2026-48842
CVE-2026-48842 PoC — Roundcube virtuser_query pre-auth SQLi
Create: 2026-09-27 11:26:19 +0000 UTC Push: 2026-09-27 11:26:20 +0000 UTC |
murrez/CVE-2026-100835
CVE-2026-100835 PoC: Edgeless Contrast <1.16.0 remote attestation relay (aTLS / CWE-295). Manifest audit (AllowedChipIDs/AllowedPIIDs), version & coordinator probe. https://pocbit.org/pocs/cve-2026-100835
Create: 2026-09-27 10:53:39 +0000 UTC Push: 2026-09-27 10:53:41 +0000 UTC |
gbuyssens/CVE-2026-34990
Local privilege escalation against a root `cupsd`.
Create: 2026-09-27 10:27:04 +0000 UTC Push: 2026-09-27 10:27:06 +0000 UTC |
gbuyssens/CVE-2026-28695-craft-rce-bypass
Authenticated, **blind** remote code execution in Craft CMS. Fix for CVE-2026-28695
Create: 2026-09-27 10:16:49 +0000 UTC Push: 2026-09-27 10:16:50 +0000 UTC |
0xc4rc3l/CVE-2026-34990-poc
Create: 2026-09-27 09:25:45 +0000 UTC Push: 2026-09-27 09:25:46 +0000 UTC |
X-Bulow/Reproduce-CVE-2025-32433
Create: 2026-09-27 09:22:01 +0000 UTC Push: 2026-09-27 09:22:02 +0000 UTC |
be-keb/CVE-2026-12227-Visual-Composer-Website-Builder-Unauthenticated-Local-File-Inclusion-LFI-
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0, This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE).
Create: 2026-09-27 09:03:34 +0000 UTC Push: 2026-09-27 09:03:35 +0000 UTC |
be-keb/CVE-2026-12227
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0, This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE).
Create: 2026-09-27 09:03:34 +0000 UTC Push: 2026-09-27 09:09:06 +0000 UTC |
Previous
-357
-356
-355
-354
-353
-352
-351
-350
Next