unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
MRdark-ops/CVE-2026-12227
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0, This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE).
Create: 2026-09-30 18:20:31 +0000 UTC Push: 2026-09-30 18:20:32 +0000 UTC |
murrez/CVE-2026-102427
CVE-2026-102427 is an unauthenticated remote code execution flaw in OrdaSoft Joomla Content Construction Kit (OS CCK) — Joomla component com_os_cck.
Create: 2026-09-30 18:12:26 +0000 UTC Push: 2026-09-30 18:12:28 +0000 UTC |
vulnace/CVE-2025-29927
POC for react2shell
Create: 2026-09-30 18:05:58 +0000 UTC Push: 2026-09-30 18:05:59 +0000 UTC |
murrez/CVE-2026-76570
CVE-2026-76570 PoC (PoCbit) — Joomla JCTables (com_jctables) <1.21.1: unauth SQL read/write via front-end JSON API getdatarow/getrow (CVSS 4.0 10.0 AT:N). check + exploit + mass. https://www.cve.org/CVERecord?id=CVE-2026-76570
Create: 2026-09-30 17:20:47 +0000 UTC Push: 2026-09-30 17:20:49 +0000 UTC |
Amoru-Bek/CVE-2025-59528-Poc
Create: 2026-09-30 16:46:38 +0000 UTC Push: 2026-09-30 16:46:39 +0000 UTC |
Pitchouneee/CVE-2026-18963
Create: 2026-09-30 16:19:25 +0000 UTC Push: 2026-09-30 16:19:26 +0000 UTC |
MRdark-ops/CVE-2026-94545-
Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC
Create: 2026-09-30 15:12:57 +0000 UTC Push: 2026-09-30 15:12:58 +0000 UTC |
BomboBombone/CVE-2026-102975
Sanitized report and local PoC for CVE-2026-102975
Create: 2026-09-30 14:25:17 +0000 UTC Push: 2026-09-30 14:25:23 +0000 UTC |
BomboBombone/CVE-2026-102973
Sanitized report and local PoC for CVE-2026-102973
Create: 2026-09-30 14:25:11 +0000 UTC Push: 2026-09-30 14:25:16 +0000 UTC |
BomboBombone/CVE-2026-102971
Sanitized report and local PoC for CVE-2026-102971
Create: 2026-09-30 14:25:05 +0000 UTC Push: 2026-09-30 14:25:10 +0000 UTC |
0xBlackash/CVE-2026-72018
CVE-2026-72018
Create: 2026-09-30 11:00:10 +0000 UTC Push: 2026-09-30 11:00:11 +0000 UTC |
wuyou6956-glitch/CVE-2026-26026-PoC
Create: 2026-09-30 10:57:26 +0000 UTC Push: 2026-09-30 10:57:34 +0000 UTC |
wuyou6956-glitch/CVE-2026-41096-POC
Create: 2026-09-30 10:57:19 +0000 UTC Push: 2026-09-30 10:57:25 +0000 UTC |
wuyou6956-glitch/cve-2026-1668-poc
Create: 2026-09-30 10:57:12 +0000 UTC Push: 2026-09-30 10:57:18 +0000 UTC |
wuyou6956-glitch/cve-2026-85706
Create: 2026-09-30 10:57:05 +0000 UTC Push: 2026-09-30 10:57:10 +0000 UTC |
JailBr3ak/CVE-2026-97347
Create: 2026-09-30 10:24:29 +0000 UTC Push: 2026-09-30 10:24:34 +0000 UTC |
CaptainAI-Labs/CaptainAI-LPE-CVE-2026-52993
Create: 2026-09-30 10:12:29 +0000 UTC Push: 2026-09-30 10:12:30 +0000 UTC |
ThierryDuval/CVENGODA2026
Create: 2026-09-30 09:52:55 +0000 UTC Push: 2026-09-30 09:52:56 +0000 UTC |
murrez/CVE-2026-102425
CVE-2026-102425 PoC (PoCbit) — Joomla Balbooa Forms (com_baforms) <2.4.3.4 unauth RCE via field shortcode injection in post-submission PHP eval(). check + exploit + mass bulk. https://pocbit.org/pocs/cve-2026-102425
Create: 2026-09-30 08:00:21 +0000 UTC Push: 2026-09-30 08:00:23 +0000 UTC |
mhtsec/CVE-2026-94545
Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC
Create: 2026-09-30 05:52:57 +0000 UTC Push: 2026-09-30 05:53:04 +0000 UTC |
Previous
-445
-444
-443
-442
-441
-440
-439
-438
Next