unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
jfs-jfs/CVE-2026-37070
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.
Create: 2026-06-15 09:55:32 +0000 UTC Push: 2026-06-15 09:59:18 +0000 UTC |
jfs-jfs/CVE-2026-37069
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.
Create: 2026-06-15 09:45:14 +0000 UTC Push: 2026-06-15 09:53:47 +0000 UTC |
jfs-jfs/CVE-2026-37068
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
Create: 2026-06-15 09:38:58 +0000 UTC Push: 2026-06-15 09:44:03 +0000 UTC |
jfs-jfs/CVE-2026-37067
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.
Create: 2026-06-15 09:34:25 +0000 UTC Push: 2026-06-15 09:37:51 +0000 UTC |
jfs-jfs/CVE-2026-37066
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
Create: 2026-06-15 09:30:17 +0000 UTC Push: 2026-06-15 09:33:19 +0000 UTC |
jfs-jfs/CVE-2026-37065
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion
Create: 2026-06-15 09:24:54 +0000 UTC Push: 2026-06-15 09:29:01 +0000 UTC |
jfs-jfs/CVE-2026-37064
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.
Create: 2026-06-15 09:14:04 +0000 UTC Push: 2026-06-15 09:21:20 +0000 UTC |
mutur4/CVE-2022-38691
Create: 2026-06-15 07:52:36 +0000 UTC Push: 2026-06-15 07:52:36 +0000 UTC |
ushst/CVE-2026-42945
CVE-2026-42945 — NGINX Rewrite Module Heap Buffer Overflow RCE checker & Metasploit module
Create: 2026-06-15 07:10:11 +0000 UTC Push: 2026-06-15 07:10:58 +0000 UTC |
Ez4rd1x1/CVE-2026-0257
testing
Create: 2026-06-15 06:49:27 +0000 UTC Push: 2026-06-15 06:49:28 +0000 UTC |
AnandJogawade/CVE-2026-48849---Stored-XSS-HTML-Injection-CSS-Injection-in-Roundcube-Webmail
This repository documents CVE-2026-48849, a Stored Cross-Site Scripting (XSS), HTML Injection, and CSS Injection vulnerability discovered in Roundcube Webmai
Create: 2026-06-15 06:43:23 +0000 UTC Push: 2026-06-15 06:43:24 +0000 UTC |
AnandJogawade/CVE-2026-48849-Roundcube-Webmail-Stored-XSS
This repository documents CVE-2026-48849, a Stored Cross-Site Scripting (XSS), HTML Injection, and CSS Injection vulnerability discovered in Roundcube Webmai
Create: 2026-06-15 06:43:23 +0000 UTC Push: 2026-06-15 06:58:23 +0000 UTC |
rootdirective-sec/CVE-2026-10795-Lab
Create: 2026-06-15 05:06:36 +0000 UTC Push: 2026-06-15 05:06:36 +0000 UTC |
jjcjgo/CVE-2026-38812-RuoYi-SQL-Injection
CVE-2026-38812 RuoYi v4.8.2 SQL Injection
Create: 2026-06-15 01:53:07 +0000 UTC Push: 2026-06-15 01:53:07 +0000 UTC |
Erik-Castro/DevSecurity
Colecao de 5 livros tecnicos open-source sobre seguranca de software em portugues (PT-BR): Security-Driven Development, DevSecOps, Analise de Malware, Concorrencia Segura e Criptografia Engenheira. C++17/20, CVEs documentados, 300K+ linhas.
Create: 2026-06-15 01:15:25 +0000 UTC Push: 2026-06-15 09:24:57 +0000 UTC |
Forklit/CVE-2026-36826
genesisQL-sqli-CVE-2026-36826
Create: 2026-06-14 22:36:28 +0000 UTC Push: 2026-06-14 22:36:28 +0000 UTC |
87achrafg-stack/CVE-2026-5513.
CVE-2026-5513 — Bookly ≤ 27.2 Stored XSS via Cookie
Create: 2026-06-14 22:24:57 +0000 UTC Push: 2026-06-14 22:24:58 +0000 UTC |
87achrafg-stack/CVE-2026-5513
Create: 2026-06-14 22:22:09 +0000 UTC Push: 2026-06-14 22:22:10 +0000 UTC |
kaleth4/-CVE-2022-30190
Create: 2026-06-14 21:06:56 +0000 UTC Push: 2026-06-14 21:06:57 +0000 UTC |
kaleth4/CVE-2022-30190
Create: 2026-06-14 21:06:56 +0000 UTC Push: 2026-06-14 21:08:12 +0000 UTC |
Previous
52
53
54
55
56
57
58
59
Next