unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
wvllxe/CVE-2026-104356-pictshare-weak-delete-code
Predictable delete_code via rand() in PictShare < 3.7.1 (CWE-338). PoC + advisory writeup.
Create: 2026-10-02 09:02:17 +0000 UTC Push: 2026-10-02 09:02:22 +0000 UTC |
wvllxe/CVE-2026-104051-pictshare-info-disclosure
Sensitive info disclosure via info API in PictShare < 3.7.1 (CWE-522). PoC + advisory writeup.
Create: 2026-10-02 09:02:11 +0000 UTC Push: 2026-10-02 09:02:16 +0000 UTC |
wvllxe/CVE-2026-100520-laranode-path-traversal
Path Traversal -> RCE in Laranode < 1.2.1 (CWE-22). PoC + advisory writeup.
Create: 2026-10-02 09:02:05 +0000 UTC Push: 2026-10-02 09:02:10 +0000 UTC |
Meniben/redmi14c-pond-cve-2026-64560
Create: 2026-10-02 08:13:48 +0000 UTC Push: 2026-10-02 08:13:49 +0000 UTC |
murrez/CVE-2026-19660
Divi Membership (DiviEngine) pre-auth admin takeover — CVE-2026-19660 paypal_param bypass. Python PoC with exploit + cookie export.
Create: 2026-10-02 05:52:17 +0000 UTC Push: 2026-10-02 05:52:18 +0000 UTC |
murrez/CVE-2026-14378
PoC for CVE-2026-14378: DevKit Pro ≤2.3.0 unauthenticated admin takeover via original_user_id cookie + revert_switch nonce. check/admin + mass scan.
Create: 2026-10-02 05:41:33 +0000 UTC Push: 2026-10-02 05:41:35 +0000 UTC |
anoxhunterdump-ctrl/CVE-2026-14378-DevKit-Pro-Auth-Bypass
Defensive analysis, patch breakdown, and detection scanner for CVE-2026-14378 (WordPress DevKit Pro Plugin <= 2.3.0).
Create: 2026-10-02 04:30:15 +0000 UTC Push: 2026-10-02 04:30:22 +0000 UTC |
anoxhunterdump-ctrl/CVE-2026-103752-Authorizer-Privilege-Escalation
Defensive analysis, patch breakdown, and passive detection scanner for CVE-2026-103752 (WordPress Authorizer Plugin <= 3.15.3).
Create: 2026-10-02 04:17:46 +0000 UTC Push: 2026-10-02 04:17:53 +0000 UTC |
abraxas/cve-2026-19553-wrap-bio
CPython - High - wrap_bio hostname skip
Create: 2026-10-02 01:46:32 +0000 UTC Push: 2026-10-02 01:46:53 +0000 UTC |
abraxas/cve-2026-19445-sni-uaf
CPython - Critical - SNI SSLContext UAF
Create: 2026-10-02 01:46:32 +0000 UTC Push: 2026-10-02 01:46:51 +0000 UTC |
0xgh057r3c0n/CVE-2026-40281
Gotenberg <= 8.30.1 unauthenticated RCE
Create: 2026-10-01 22:22:17 +0000 UTC Push: 2026-10-01 22:22:18 +0000 UTC |
ShadowForge-Cyber/CVE-2026-104286-POC
Create: 2026-10-01 22:15:42 +0000 UTC Push: 2026-10-01 22:15:44 +0000 UTC |
pervinzahidli/CVE-2026-104110
Unauthenticated disclosure of internal folder path, client email, and upload policy for FileRise Pro client portals via /api/pro/portals/get.php
Create: 2026-10-01 18:55:16 +0000 UTC Push: 2026-10-01 18:55:17 +0000 UTC |
pervinzahidli/CVE-2026-103977
Session-scoped TOTP rate limiting permits repeated verification attempts
Create: 2026-10-01 18:48:25 +0000 UTC Push: 2026-10-01 18:48:26 +0000 UTC |
yel1337/CVE-2025-47947
POC for libapache2-mod-security2
Create: 2026-10-01 18:20:00 +0000 UTC Push: 2026-10-01 18:20:02 +0000 UTC |
Hassham1/CVE-2026-62059-ultimate-member-sqli-poc
Create: 2026-10-01 16:09:44 +0000 UTC Push: 2026-10-01 16:10:05 +0000 UTC |
CheLover86/CVE-2017-9841
I like CVEs!
Create: 2026-10-01 15:47:31 +0000 UTC Push: 2026-10-01 15:47:34 +0000 UTC |
securifera/CVE-2026-90817
REDCap DataImport RCE
Create: 2026-10-01 15:34:52 +0000 UTC Push: 2026-10-01 15:34:53 +0000 UTC |
canhieu/cve-2026-100671-poc
Create: 2026-10-01 15:25:50 +0000 UTC Push: 2026-10-01 15:25:51 +0000 UTC |
aorozco-sys/CVE-2026-90907
CVE-2026-90907 (CVSS 6.9) — Joomla! CMS unauthorized user account creation via com_users profile.save (authorization bypass). Non-destructive checker + authorized-use exploit PoC. Fixed in 5.4.9 / 6.1.4.
Create: 2026-10-01 15:14:28 +0000 UTC Push: 2026-10-01 15:14:34 +0000 UTC |
Previous
-494
-493
-492
-491
-490
-489
-488
-487
Next