unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
0xmrma/CVE-2026-34213
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
Create: 2026-06-26 12:43:11 +0000 UTC Push: 2026-06-26 12:43:12 +0000 UTC |
0xmrma/CVE-2026-34212
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
Create: 2026-06-26 12:41:41 +0000 UTC Push: 2026-06-26 12:41:42 +0000 UTC |
0xmrma/CVE-2026-33146
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
Create: 2026-06-26 12:25:56 +0000 UTC Push: 2026-06-26 12:25:57 +0000 UTC |
izxci/CVE-2026-54807
CVE-2026-54807 WooCommerce Privilege Escalation ║ ║ Unauthenticated Admin Role Assignment via Reg. Form
Create: 2026-06-26 12:11:01 +0000 UTC Push: 2026-06-26 12:11:02 +0000 UTC |
e-corp-demo/CVE-2026-44788
Create: 2026-06-26 11:18:57 +0000 UTC Push: 2026-06-26 11:18:58 +0000 UTC |
aexdyhaxor/CVE-2026-43503-DirtyClone
Create: 2026-06-26 11:06:01 +0000 UTC Push: 2026-06-26 11:06:23 +0000 UTC |
0xBlackash/CVE-2026-8461
CVE-2026-8461
Create: 2026-06-26 07:23:34 +0000 UTC Push: 2026-06-26 07:23:35 +0000 UTC |
huseyinstif/CVE-2026-13036-PoC
PoC for CVE-2026-13036 — Use-after-free in Blink WidgetBase::UpdateSurfaceAndScreenInfo (Chrome < 149.0.7827.197)
Create: 2026-06-26 06:38:17 +0000 UTC Push: 2026-06-26 06:38:20 +0000 UTC |
offseckit/CVE-2026-24207-triton
PoC + analysis for CVE-2026-24207 / CVE-2026-24206 — NVIDIA Triton SageMaker & Vertex AI auth-restriction bypass + RCE chain
Create: 2026-06-26 06:30:29 +0000 UTC Push: 2026-06-26 06:30:32 +0000 UTC |
offseckit/CVE-2026-24207
CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.
Create: 2026-06-26 06:30:29 +0000 UTC Push: 2026-06-26 06:30:32 +0000 UTC |
gagaltotal/CVE-2026-26980-Ghost-CMS-Api
CVE-2026-26980 - Ghost CMS Content API SQL Injection
Create: 2026-06-26 05:57:53 +0000 UTC Push: 2026-06-26 05:57:54 +0000 UTC |
12hrformat/CVE-2026-35273-POC
Create: 2026-06-26 05:21:08 +0000 UTC Push: 2026-06-26 05:21:08 +0000 UTC |
mooder1/dirtyclone-CVE-2026-43503
Create: 2026-06-26 00:20:58 +0000 UTC Push: 2026-06-26 00:22:35 +0000 UTC |
0xBlackash/CVE-2026-43503
CVE-2026-43503
Create: 2026-06-25 21:58:41 +0000 UTC Push: 2026-06-25 21:58:42 +0000 UTC |
mirackayikci/CVE-2026-55584
CVE-2026-55584 — phpSysInfo IP Allowlist Bypass
Create: 2026-06-25 18:29:12 +0000 UTC Push: 2026-06-25 18:29:14 +0000 UTC |
tech-mainak/CVE-2023-45866---Blue-exploit
POC for CVE-2023-45866 affecting Latest Android devices.
Create: 2026-06-25 17:50:37 +0000 UTC Push: 2026-06-25 17:50:37 +0000 UTC |
joaquinrrr/CVE-2025-8110
PoC exploit for CVE-2025-8110
Create: 2026-06-25 16:48:18 +0000 UTC Push: 2026-06-25 16:48:19 +0000 UTC |
do4choo/CVE-2026-3227
Create: 2026-06-25 16:31:07 +0000 UTC Push: 2026-06-25 16:31:08 +0000 UTC |
hacbs-release-tests/collectors-no-cve-c87b201b
Create: 2026-06-25 13:31:35 +0000 UTC Push: 2026-06-25 13:32:05 +0000 UTC |
renzi25031469/CVE-2026-4253-Scanner
Non-destructive vulnerability scanner for NGINX HTTP/3 (ngx_http_v3_module). It ONLY performs a safe probe: opens an HTTP/3 (QUIC) connection, sends a single HEAD request and inspects the `Server` response header. It NEVER attempts to reopen a QPACK encoder stream or trigger the use-after-free.
Create: 2026-06-25 12:11:30 +0000 UTC Push: 2026-06-25 12:11:31 +0000 UTC |
Previous
36
37
38
39
40
41
42
43
Next