unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
ixZODiAK/CVE-2025-8110
Gogs service Exploit and get the root user
Create: 2026-07-21 18:01:04 +0000 UTC Push: 2026-07-21 18:01:05 +0000 UTC |
Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
PoC detector & safe validator for the WP2Shell WordPress vulnerability chain: CVE-2026-63030 (REST batch-route confusion) + CVE-2026-60137 (author__not_in SQL injection). For authorized security testing only.
Create: 2026-07-21 17:51:33 +0000 UTC Push: 2026-07-21 17:51:37 +0000 UTC |
mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
Create: 2026-07-21 17:44:09 +0000 UTC Push: 2026-07-21 17:44:10 +0000 UTC |
danielissaq/-PaperCut-CVE-2023-27350-
Create: 2026-07-21 17:20:53 +0000 UTC Push: 2026-07-21 17:20:53 +0000 UTC |
h1dden30/cve-2025-11705-poc
writeup for cve-2025-11705
Create: 2026-07-21 17:15:59 +0000 UTC Push: 2026-07-21 17:16:00 +0000 UTC |
6t2kydmp8k-jpg/CVE-2025-55182-Vulnerability-Proof-of-Concept-Group-Project-
Create: 2026-07-21 17:03:27 +0000 UTC Push: 2026-07-21 17:03:48 +0000 UTC |
c0gnit00/CVE-2025-32432
Exploit, POC for CVE-2025-32432, CraftCMS2Shell
Create: 2026-07-21 16:52:22 +0000 UTC Push: 2026-07-21 16:52:23 +0000 UTC |
iqx6889/CVE-2026-52813-Gogs-RCE
CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive version scanner. No weaponized PoC.
Create: 2026-07-21 15:19:49 +0000 UTC Push: 2026-07-21 15:20:00 +0000 UTC |
pvharmo2/cve-repro-cve-2025-47928
Create: 2026-07-21 14:19:29 +0000 UTC Push: 2026-07-21 14:19:30 +0000 UTC |
oscerd/CVE-2026-53913
PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required roles/permissions the token is never verified, so any forged/garbage bearer token bypasses authentication (unauthenticated RCE). Fixed in 4.18.3/4.21.0.
Create: 2026-07-21 12:46:27 +0000 UTC Push: 2026-07-21 12:46:30 +0000 UTC |
Debajyoti0-0/CVE-2026-27654
Create: 2026-07-21 12:05:07 +0000 UTC Push: 2026-07-21 12:05:08 +0000 UTC |
Debajyoti0-0/CVE-2026-27654-PoC
Proof-of-Concept and technical analysis for CVE-2026-27654, a heap-based buffer overflow vulnerability in the NGINX HTTP WebDAV module, including root cause analysis, reproduction, and mitigation.
Create: 2026-07-21 12:05:07 +0000 UTC Push: 2026-07-21 12:26:50 +0000 UTC |
jaf0rk/CVE-2026-9973-exploit
Create: 2026-07-21 11:57:43 +0000 UTC Push: 2026-07-21 11:57:43 +0000 UTC |
Petalrain224/CVE-2026-43499-Redmi-Turbo5
Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege
Create: 2026-07-21 11:28:41 +0000 UTC Push: 2026-07-21 11:28:42 +0000 UTC |
0xdak/CVE-2026-9198_exploit
Create: 2026-07-21 11:14:59 +0000 UTC Push: 2026-07-21 11:15:06 +0000 UTC |
sentinel-aidefense/CVE-2025-20352
CVE-2025-20352 Research writeup
Create: 2026-07-21 10:39:27 +0000 UTC Push: 2026-07-21 10:39:51 +0000 UTC |
BardLaudian/CVE-2025-64512
Create: 2026-07-21 09:56:44 +0000 UTC Push: 2026-07-21 09:56:44 +0000 UTC |
oscerd/CVE-2026-49365
PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.
Create: 2026-07-21 09:55:57 +0000 UTC Push: 2026-07-21 09:56:01 +0000 UTC |
KuniNogu/drupal-openai-provider-ssrf-cve-2026-13233
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.
Create: 2026-07-21 09:27:25 +0000 UTC Push: 2026-07-21 09:37:51 +0000 UTC |
oscerd/CVE-2026-49099
PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and overrides the producer's configured SOQL (SOQL injection / broken access control). Fixed in 4.14.8/4.18.3/4.21.0.
Create: 2026-07-21 09:20:20 +0000 UTC Push: 2026-07-21 09:20:23 +0000 UTC |
Previous
-2
-1
0
1
2
3
4
5
Next