unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
e5dfdd568a75282b712b6d93a7a18e12/CVE-2026-22777
CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303
Create: 2026-09-28 10:09:06 +0000 UTC Push: 2026-09-28 10:09:07 +0000 UTC |
FollowerSeize/CVE-2026-88772-POC
CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)
Create: 2026-09-28 09:56:39 +0000 UTC Push: 2026-09-28 09:56:44 +0000 UTC |
murrez/CVE-2026-100721
CVE-2026-100721 PoC: vm2 <3.12.2 NodeVM external allowlist bypass → sandbox escape / host RCE. Local Node lab (evil-left-pad), remote sandbox API mass exploit, colorful CLI. PoCbit — https://pocbit.org/pocs/cve-2026-100721
Create: 2026-09-28 09:45:48 +0000 UTC Push: 2026-09-28 09:45:51 +0000 UTC |
EXEcution-py/CVE-2026-88771-POC
Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total
Create: 2026-09-28 09:16:23 +0000 UTC Push: 2026-09-28 09:16:25 +0000 UTC |
EQSTLab/CVE-2026-6951
simple-git RCE
Create: 2026-09-28 08:35:35 +0000 UTC Push: 2026-09-28 08:35:36 +0000 UTC |
murrez/CVE-2026-82384
CVE-2026-82384 PoC: Apache Roller 6.1.5 unauthenticated XML-RPC ex:serializable Java deserialization (pre-auth RCE). Check, ysoserial exploit, mass bulk scanning, colored CLI. PoCbit — https://pocbit.org/pocs/cve-2026-82384
Create: 2026-09-28 08:24:47 +0000 UTC Push: 2026-09-28 08:25:28 +0000 UTC |
4ybrick/CVE-2026-100903
GEOritm CVE
Create: 2026-09-28 08:20:25 +0000 UTC Push: 2026-09-28 08:25:25 +0000 UTC |
murrez/CVE-2026-93958
CVE-2026-93958 PoC: D-Link R95 BE9500 DHMAPI SetTimeSettings NTPServer authenticated root command injection. DHMAPI login, RCE verify, mass bulk exploit mode, colored CLI. https://pocbit.org/pocs/cve-2026-93958
Create: 2026-09-28 08:13:41 +0000 UTC Push: 2026-09-28 08:14:05 +0000 UTC |
carsam2021/CVE-2026-88772
CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS probe. CTX697096; active exploitation reported. https://pocbit.org/pocs/cve-2026-88772
Create: 2026-09-28 07:39:04 +0000 UTC Push: 2026-09-27 20:26:07 +0000 UTC |
EQSTLab/CVE-2026-85706
GitLab Unauthenticated Arbitrary File Read
Create: 2026-09-28 04:47:10 +0000 UTC Push: 2026-09-28 04:47:11 +0000 UTC |
murrez/CVE-2026-85984
Create: 2026-09-28 04:25:20 +0000 UTC Push: 2026-09-28 04:25:21 +0000 UTC |
Noorkhalel/CVE-2026-34990-CUPS-LPE-PoC
Create: 2026-09-28 03:21:43 +0000 UTC Push: 2026-09-28 03:22:13 +0000 UTC |
bara-almustafa/CVE-2026-34990-POC
CVE-2026-34990 — CUPS <= 2.4.16 Local Privilege Escalation
Create: 2026-09-28 02:40:44 +0000 UTC Push: 2026-09-28 02:40:45 +0000 UTC |
antid00t/CVE-2026-78006-CVE-2026-78159
CVE-2026-78006 + CVE-2026-78159 Mass Exploit
Create: 2026-09-28 00:45:37 +0000 UTC Push: 2026-09-28 00:45:38 +0000 UTC |
Boreas37/CVE-2026-88008-PoC
CVE-2026-88008 - Traefik (<=2.11.56 / <=3.7.12): a client-controlled h2c upgrade tunnels past routers and middleware (BasicAuth/ForwardAuth/IPAllowList), unauthorised access + no access logging. Stdlib-only Python PoC + real Jetty h2c lab, verified on v3.7.12 vs v3.7.13.
Create: 2026-09-27 22:58:31 +0000 UTC Push: 2026-09-27 22:58:38 +0000 UTC |
gdfurr98/ply-cve-2025-56005-lab
Lab demonstrating that CVE-2025-56005 is real and does allow arbitrary code execution at a minimum (the debate about RCE notwithstanding here), and shows that ply-safepickle does block the exploit path.
Create: 2026-09-27 22:49:37 +0000 UTC Push: 2026-09-27 22:49:38 +0000 UTC |
Boreas37/CVE-2026-71963-PoC
CVE-2026-71963 - Hermes Agent 0.18.2-0.21.0 RCE via a repository-delivered .git/config (core.fsmonitor). Stdlib-only Python, verified on real 0.21.0 with a clean negative control on the fixed build.
Create: 2026-09-27 22:31:47 +0000 UTC Push: 2026-09-27 22:31:55 +0000 UTC |
khush-613/CVE-2026-44011-poc
Create: 2026-09-27 22:01:43 +0000 UTC Push: 2026-09-27 22:01:44 +0000 UTC |
ImperfectP/CVE-2026-600004
Functional script
Create: 2026-09-27 21:50:13 +0000 UTC Push: 2026-09-27 21:50:14 +0000 UTC |
khush-613/CVE-2026-34990-poc
Create: 2026-09-27 21:38:26 +0000 UTC Push: 2026-09-27 21:38:27 +0000 UTC |
Previous
-379
-378
-377
-376
-375
-374
-373
-372
Next