unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
nullwhisper/CVE-2026-14282
GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)
Create: 2026-08-13 00:27:20 +0000 UTC Push: 2026-08-13 00:27:27 +0000 UTC |
nullwhisper/CVE-2026-14840
Create: 2026-08-13 00:01:42 +0000 UTC Push: 2026-08-13 00:01:43 +0000 UTC |
aramosf/CVE-2026-24031
CVE-2026-24031 Dovecot 2.4.0/3.1.0 SQL authentication bypass (auth bypass + user enumeration) PoC
Create: 2026-08-12 23:19:05 +0000 UTC Push: 2026-08-12 23:19:22 +0000 UTC |
enriquenegri-cyberlaw/boa-cve-2009-4496-analysis
Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.
Create: 2026-08-12 22:11:12 +0000 UTC Push: 2026-08-12 22:11:12 +0000 UTC |
kagancapar/CVE-2026-54984
CVE-2026-54984 / ZDI-26-543: Windows ICC file parsing out-of-bounds write (CWE-122, CVSS 7.8)
Create: 2026-08-12 21:03:20 +0000 UTC Push: 2026-08-12 21:03:20 +0000 UTC |
aisha-jimoh/cve-2025-55182-react2shell-analysis
Create: 2026-08-12 19:57:15 +0000 UTC Push: 2026-08-12 19:57:15 +0000 UTC |
matesz44/cve-2026-39987
CVE-2026-39987 PoC: Marimo<0.23.0 Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Create: 2026-08-12 19:12:11 +0000 UTC Push: 2026-08-12 19:12:12 +0000 UTC |
Boreas37/CVE-2026-41452-PoC
CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5
Create: 2026-08-12 18:35:57 +0000 UTC Push: 2026-08-12 18:35:58 +0000 UTC |
Boreas37/CVE-2026-73034-PoC
CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff
Create: 2026-08-12 18:35:23 +0000 UTC Push: 2026-08-12 18:35:27 +0000 UTC |
Boreas37/CVE-2026-33267-PoC
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4
Create: 2026-08-12 17:18:32 +0000 UTC Push: 2026-08-12 17:18:33 +0000 UTC |
Boreas37/CVE-2026-17544-PoC
CVE-2026-17544 — PHP bcmath bccomp() OOB write (stack smashing). Verified: crash on 8.4.23/8.5.8, fixed in 8.4.24. GHSA-x692-q9x7-8c3f
Create: 2026-08-12 17:17:50 +0000 UTC Push: 2026-08-12 17:17:54 +0000 UTC |
686f6c61/POC-CopyEscape-CVE-2026-17106
PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.
Create: 2026-08-12 16:41:52 +0000 UTC Push: 2026-08-12 16:41:56 +0000 UTC |
guard-wait/CVE-2026-64563_EXP
关于CVE-2026-64563未完全验证的一种利用思路
Create: 2026-08-12 16:35:16 +0000 UTC Push: 2026-08-12 16:35:17 +0000 UTC |
yora1928/CVE-2026-48908-by-yora
Passive security checker for CVE-2026-48908 affecting SP Page Builder.
Create: 2026-08-12 16:12:13 +0000 UTC Push: 2026-08-12 16:12:13 +0000 UTC |
aramosf/CVE-2026-68398
CVE-2026-68398 Ubuntu PPPoL2TP use-after-free local privilege escalation
Create: 2026-08-12 15:04:01 +0000 UTC Push: 2026-08-12 15:26:02 +0000 UTC |
Gutierre0x80/CVE-2026-59827
Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code execution.
Create: 2026-08-12 14:34:15 +0000 UTC Push: 2026-08-12 14:34:16 +0000 UTC |
HORKimhab/CVE-2026-28956
CVE-2026-28956 - Draft or TODO
Create: 2026-08-12 14:23:48 +0000 UTC Push: 2026-08-12 14:24:28 +0000 UTC |
0xBlackash/CVE-2026-72898
CVE-2026-72898
Create: 2026-08-12 13:54:46 +0000 UTC Push: 2026-08-12 13:54:47 +0000 UTC |
Knz-source/CVE-2026-23111-POC-noddlenpottato
s
Create: 2026-08-12 13:23:42 +0000 UTC Push: 2026-08-12 13:23:43 +0000 UTC |
QM4RS/CVE-2026-0075
Create: 2026-08-12 13:09:06 +0000 UTC Push: 2026-08-12 13:09:11 +0000 UTC |
Previous
56
57
58
59
60
61
62
63
Next