unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
NicPWNs/CVE-2026-62183
Apache Syncope: User self-service privilege escalation
Create: 2026-07-20 22:56:04 +0000 UTC Push: 2026-07-20 22:56:05 +0000 UTC |
hakaioffsec/CVE-2026-12191
PoC for CVE-2026-12191
Create: 2026-07-20 19:23:29 +0000 UTC Push: 2026-07-20 19:23:30 +0000 UTC |
Ch4120N/CVE-2026-63030
Create: 2026-07-20 18:20:41 +0000 UTC Push: 2026-07-20 18:20:42 +0000 UTC |
mysterioinfinino-rgb/YellowKey-Bitlocker-CVE-2026-45585
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
Create: 2026-07-20 18:10:40 +0000 UTC Push: 2026-07-20 18:10:41 +0000 UTC |
yellowkeys/YellowKey-Bitlocker-CVE-2026-45585
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
Create: 2026-07-20 18:10:40 +0000 UTC Push: 2026-07-20 18:14:38 +0000 UTC |
CerberusMrXi/CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.
Create: 2026-07-20 17:46:14 +0000 UTC Push: 2026-07-20 17:46:15 +0000 UTC |
oscerd/CVE-2026-49098
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.
Create: 2026-07-20 16:39:45 +0000 UTC Push: 2026-07-20 16:39:48 +0000 UTC |
baktistr/cve-2026-23550-poc
Create: 2026-07-20 16:03:51 +0000 UTC Push: 2026-07-20 16:03:52 +0000 UTC |
BishopFox/CVE-2026-11374-check
Detection script for CVE-2026-11374
Create: 2026-07-20 15:52:06 +0000 UTC Push: 2026-07-20 15:52:10 +0000 UTC |
UnusualGiraffe/PoC-Unauthenticated-RCE-in-WatchGuard-Fireware-12.7-Build-640389-CVE-2025-9242
Version-pinned archival PoC for CVE-2025-9242 on WatchGuard Fireware 12.7 build 640389. Includes safe detection, offline payload analysis, and an explicitly gated reverse-shell exploit using a caller-supplied IPv4 callback endpoint.
Create: 2026-07-20 15:11:40 +0000 UTC Push: 2026-07-20 15:11:40 +0000 UTC |
dinhvaren/cve-2026-55685-PoC
Create: 2026-07-20 14:22:29 +0000 UTC Push: 2026-07-20 14:22:30 +0000 UTC |
soverineg/cve-2026-41940-PoC
A cPanel and WHM authentication bypassing tool
Create: 2026-07-20 14:15:54 +0000 UTC Push: 2026-07-20 14:23:26 +0000 UTC |
HELLBOY3110/cve-2026-16219-croogo-lab
Create: 2026-07-20 14:01:52 +0000 UTC Push: 2026-07-20 14:01:53 +0000 UTC |
oscerd/CVE-2026-49097
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.
Create: 2026-07-20 13:41:41 +0000 UTC Push: 2026-07-20 13:41:44 +0000 UTC |
berraesen/apache-cve-2021-42013-lab
Docker ortamında Apache HTTP Server 2.4.49 (CVE-2021-42013) zafiyetinin gösterildiği laboratuvar çalışması.
Create: 2026-07-20 13:24:03 +0000 UTC Push: 2026-07-20 13:24:05 +0000 UTC |
oscerd/CVE-2026-49086
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.
Create: 2026-07-20 12:12:06 +0000 UTC Push: 2026-07-20 12:12:10 +0000 UTC |
0x00phantom-hat/CVE-2026-5029-Exploit
Create: 2026-07-20 11:43:06 +0000 UTC Push: 2026-07-20 11:43:07 +0000 UTC |
OffByOn3/CVE-2026-63030-Wp2Shell
WordPress REST API SQLi to RCE (CVE-2026-63030)
Create: 2026-07-20 10:59:36 +0000 UTC Push: 2026-07-20 11:02:41 +0000 UTC |
Dungsocool/CVE-2024-23897
Create: 2026-07-20 10:59:31 +0000 UTC Push: 2026-07-20 10:59:52 +0000 UTC |
N3xtGenH4cker/CVE-2026-63030-CVE-2026-60137_wp2shell-checker
Create: 2026-07-20 10:25:32 +0000 UTC Push: 2026-07-20 10:25:33 +0000 UTC |
Previous
1
2
3
4
5
6
7
8
Next