{"pocs":[{"id":"1337518937","cve_id":"CVE-2026-20079","name":"CVE-2026-20079","owner":"CyberAuth","full_name":"CyberAuth\/CVE-2026-20079","html_url":"https:\/\/github.com\/CyberAuth\/CVE-2026-20079","description":"Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center.","stargazers_count":"0","vuln_description":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.\r\n\r This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.","created_at":"2026-08-18 03:36:35","updated_at":"2026-08-18 03:39:16","pushed_at":"2026-08-18 03:36:38","inserted_at":"2026-08-18 04:37:11"},{"id":"1337424339","cve_id":"CVE-2026-39154","name":"Wildfire","owner":"defineid","full_name":"defineid\/Wildfire","html_url":"https:\/\/github.com\/defineid\/Wildfire","description":"CVE-2026-39154 \u00b7 Stored XSS in CometChat JS SDK","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-18 02:03:52","updated_at":"2026-08-18 02:07:40","pushed_at":"2026-08-18 02:03:59","inserted_at":"2026-08-18 04:37:11"},{"id":"1337424196","cve_id":"CVE-2026-6765","name":"SkeletonKey","owner":"defineid","full_name":"defineid\/SkeletonKey","html_url":"https:\/\/github.com\/defineid\/SkeletonKey","description":"CVE-2026-6765 \u00b7 Test only FormAutofill handlers exposed in Firefox","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-18 02:03:44","updated_at":"2026-08-18 02:06:48","pushed_at":"2026-08-18 02:03:49","inserted_at":"2026-08-18 04:37:12"},{"id":"1337424077","cve_id":"CVE-2026-74970","name":"Trespasser","owner":"defineid","full_name":"defineid\/Trespasser","html_url":"https:\/\/github.com\/defineid\/Trespasser","description":"CVE-2026-74970 \u00b7 Fission site isolation bypass in Firefox WebRender","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-18 02:03:37","updated_at":"2026-08-18 02:06:56","pushed_at":"2026-08-18 02:03:42","inserted_at":"2026-08-18 04:37:12"},{"id":"1337423975","cve_id":"CVE-2026-74945","name":"Palimpsest","owner":"defineid","full_name":"defineid\/Palimpsest","html_url":"https:\/\/github.com\/defineid\/Palimpsest","description":"CVE-2026-74945 \u00b7 Uninitialized heap disclosure via a crafted web font (sec-high)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-18 02:03:31","updated_at":"2026-08-18 02:07:16","pushed_at":"2026-08-18 02:03:35","inserted_at":"2026-08-18 04:37:12"},{"id":"1337423814","cve_id":"CVE-2026-74943","name":"Revenant","owner":"defineid","full_name":"defineid\/Revenant","html_url":"https:\/\/github.com\/defineid\/Revenant","description":"CVE-2026-74943 \u00b7 Use after free in Firefox RasterImage (sec-high)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-18 02:03:24","updated_at":"2026-08-18 02:06:52","pushed_at":"2026-08-18 02:03:29","inserted_at":"2026-08-18 04:37:12"},{"id":"1337366078","cve_id":"CVE-2026-33017","name":"CVE-2026-33017-FireFlow","owner":"l4st98","full_name":"l4st98\/CVE-2026-33017-FireFlow","html_url":"https:\/\/github.com\/l4st98\/CVE-2026-33017-FireFlow","description":"CVE-2026-33017, vuln in langflow.","stargazers_count":"0","vuln_description":"Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST \/api\/v1\/build_public_tmp\/{flow_id}\/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed \/api\/v1\/validate\/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.","created_at":"2026-08-18 01:12:01","updated_at":"2026-08-18 01:29:53","pushed_at":"2026-08-18 01:28:44","inserted_at":"2026-08-18 04:37:11"},{"id":"1337274592","cve_id":"CVE-2025-21479","name":"vivo_iqoo_neo_9_root_research_on_CVE-2025-21479","owner":"linux-tools","full_name":"linux-tools\/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479","html_url":"https:\/\/github.com\/linux-tools\/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479","description":"iQOO Neo9 (PD2338C) \u514d\u89e3\u9501 Caps-Root \u5de5\u5177** \u2014 \u57fa\u4e8e CVE-2025-21479 (Adreno GPU SDS) \u7684\u4efb\u610f\u7269\u7406\u5199\u63d0\u6743\u65b9\u6848","stargazers_count":"0","vuln_description":"Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.","created_at":"2026-08-17 23:37:05","updated_at":"2026-08-17 23:41:27","pushed_at":"2026-08-17 23:41:21","inserted_at":"2026-08-18 04:37:10"},{"id":"1337244671","cve_id":"CVE-2026-40345","name":"CVE-2026-40345","owner":"Jvr2022","full_name":"Jvr2022\/CVE-2026-40345","html_url":"https:\/\/github.com\/Jvr2022\/CVE-2026-40345","description":"A poc and write-up for CVE-2026-40345","stargazers_count":"1","vuln_description":null,"created_at":"2026-08-17 23:06:41","updated_at":"2026-08-17 23:51:38","pushed_at":"2026-08-17 23:08:41","inserted_at":"2026-08-18 04:37:11"},{"id":"1337134382","cve_id":"CVE-2026-56852","name":"golang-x-text","owner":"katekeiroz-dev","full_name":"katekeiroz-dev\/golang-x-text","html_url":"https:\/\/github.com\/katekeiroz-dev\/golang-x-text","description":"golang.org\/x\/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 21:24:29","updated_at":"2026-08-17 21:27:03","pushed_at":"2026-08-17 21:25:20","inserted_at":"2026-08-17 22:37:12"},{"id":"1337059712","cve_id":"CVE-2026-41042","name":"cve-2026-41042","owner":"Lulztigre","full_name":"Lulztigre\/cve-2026-41042","html_url":"https:\/\/github.com\/Lulztigre\/cve-2026-41042","description":"POC for CVE-2026-41042","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 20:15:58","updated_at":"2026-08-17 20:32:40","pushed_at":"2026-08-17 20:31:43","inserted_at":"2026-08-17 22:37:12"},{"id":"1336992068","cve_id":"CVE-2026-59310","name":"CVE-2026-59310","owner":"BiuTrap","full_name":"BiuTrap\/CVE-2026-59310","html_url":"https:\/\/github.com\/BiuTrap\/CVE-2026-59310","description":"CVE-2026-59310 PoC","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 19:09:51","updated_at":"2026-08-17 19:18:20","pushed_at":"2026-08-17 19:15:47","inserted_at":"2026-08-17 22:37:13"},{"id":"1336972874","cve_id":"CVE-2025-55182","name":"React2Shell","owner":"PhanHoangKhang","full_name":"PhanHoangKhang\/React2Shell","html_url":"https:\/\/github.com\/PhanHoangKhang\/React2Shell","description":"Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).","stargazers_count":"0","vuln_description":"A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.","created_at":"2026-08-17 18:51:01","updated_at":"2026-08-17 20:14:18","pushed_at":"2026-08-17 20:11:57","inserted_at":"2026-08-17 22:37:12"},{"id":"1336860764","cve_id":"CVE-2026-68138","name":"CVE-2026-68138","owner":"jangkrikkbozz","full_name":"jangkrikkbozz\/CVE-2026-68138","html_url":"https:\/\/github.com\/jangkrikkbozz\/CVE-2026-68138","description":"CVE-2026-68138 Linux Local Privilege Escalation Exploit","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 17:04:51","updated_at":"2026-08-17 17:24:13","pushed_at":"2026-08-17 17:23:09","inserted_at":"2026-08-17 22:37:13"},{"id":"1336848000","cve_id":"CVE-2026-59310","name":"CVE-2026-59310","owner":"HORKimhab","full_name":"HORKimhab\/CVE-2026-59310","html_url":"https:\/\/github.com\/HORKimhab\/CVE-2026-59310","description":"CVE-2026-59310","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 16:51:46","updated_at":"2026-08-17 17:29:14","pushed_at":"2026-08-17 17:28:23","inserted_at":"2026-08-17 22:37:13"},{"id":"1336829325","cve_id":"CVE-2026-68138","name":"CVE-2026-68138","owner":"suominen","full_name":"suominen\/CVE-2026-68138","html_url":"https:\/\/github.com\/suominen\/CVE-2026-68138","description":"Tracking CVE-2026-68138, the Linux kernel net\/sched qdisc rate-table use-after-free","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 16:33:31","updated_at":"2026-08-17 18:16:52","pushed_at":"2026-08-17 18:15:16","inserted_at":"2026-08-17 22:37:13"},{"id":"1336660297","cve_id":"CVE-2018-8611","name":"cve-2018-8611","owner":"ahm3dgg","full_name":"ahm3dgg\/cve-2018-8611","html_url":"https:\/\/github.com\/ahm3dgg\/cve-2018-8611","description":"CVE-2018-8611 PrivEsc Exploit","stargazers_count":"0","vuln_description":"An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka \"Windows Kernel Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.","created_at":"2026-08-17 13:20:38","updated_at":"2026-08-17 13:23:48","pushed_at":"2026-08-17 13:22:49","inserted_at":"2026-08-17 16:37:08"},{"id":"1336615508","cve_id":"CVE-2026-64747","name":"ave263-chain","owner":"yiyeshi0-hash","full_name":"yiyeshi0-hash\/ave263-chain","html_url":"https:\/\/github.com\/yiyeshi0-hash\/ave263-chain","description":"iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 12:24:57","updated_at":"2026-08-17 15:49:03","pushed_at":"2026-08-17 15:48:57","inserted_at":"2026-08-17 16:37:12"},{"id":"1336567205","cve_id":"CVE-2026-74251","name":"CVE-2026-74251","owner":"toanln-cov","full_name":"toanln-cov\/CVE-2026-74251","html_url":"https:\/\/github.com\/toanln-cov\/CVE-2026-74251","description":"Unauthenticated SQL Injection via Attribute Filter in Phoca Cart","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 11:20:42","updated_at":"2026-08-17 11:55:07","pushed_at":"2026-08-17 11:55:00","inserted_at":"2026-08-17 16:37:12"},{"id":"1336329781","cve_id":"CVE-2026-18366","name":"CVE-2026-18366","owner":"Nxploited","full_name":"Nxploited\/CVE-2026-18366","html_url":"https:\/\/github.com\/Nxploited\/CVE-2026-18366","description":"Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 05:21:02","updated_at":"2026-08-17 05:23:45","pushed_at":"2026-08-17 05:23:11","inserted_at":"2026-08-17 10:37:11"},{"id":"1336327364","cve_id":"CVE-2026-71203","name":"CVE-2026-71203-PoC","owner":"Nel-droid","full_name":"Nel-droid\/CVE-2026-71203-PoC","html_url":"https:\/\/github.com\/Nel-droid\/CVE-2026-71203-PoC","description":"PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 05:17:56","updated_at":"2026-08-17 05:18:28","pushed_at":"2026-08-17 05:18:01","inserted_at":"2026-08-17 10:37:11"},{"id":"1336327278","cve_id":"CVE-2026-71204","name":"CVE-2026-71204-PoC","owner":"Nel-droid","full_name":"Nel-droid\/CVE-2026-71204-PoC","html_url":"https:\/\/github.com\/Nel-droid\/CVE-2026-71204-PoC","description":"PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 05:17:50","updated_at":"2026-08-17 05:18:14","pushed_at":"2026-08-17 05:17:54","inserted_at":"2026-08-17 10:37:11"},{"id":"1336327108","cve_id":"CVE-2026-71205","name":"CVE-2026-71205-PoC","owner":"Nel-droid","full_name":"Nel-droid\/CVE-2026-71205-PoC","html_url":"https:\/\/github.com\/Nel-droid\/CVE-2026-71205-PoC","description":"PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 05:17:37","updated_at":"2026-08-17 05:18:18","pushed_at":"2026-08-17 05:17:41","inserted_at":"2026-08-17 10:37:11"},{"id":"1336327023","cve_id":"CVE-2026-72585","name":"CVE-2026-72585-PoC","owner":"Nel-droid","full_name":"Nel-droid\/CVE-2026-72585-PoC","html_url":"https:\/\/github.com\/Nel-droid\/CVE-2026-72585-PoC","description":"PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 05:17:31","updated_at":"2026-08-17 05:17:41","pushed_at":"2026-08-17 05:17:35","inserted_at":"2026-08-17 10:37:11"},{"id":"1336326953","cve_id":"CVE-2026-71206","name":"CVE-2026-71206-PoC","owner":"Nel-droid","full_name":"Nel-droid\/CVE-2026-71206-PoC","html_url":"https:\/\/github.com\/Nel-droid\/CVE-2026-71206-PoC","description":"PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 05:17:25","updated_at":"2026-08-17 05:18:03","pushed_at":"2026-08-17 05:17:29","inserted_at":"2026-08-17 10:37:11"},{"id":"1336113865","cve_id":"CVE-2026-8508","name":"zyxel-social-login-bypass-cve-2026-8508","owner":"minanagehsalalma","full_name":"minanagehsalalma\/zyxel-social-login-bypass-cve-2026-8508","html_url":"https:\/\/github.com\/minanagehsalalma\/zyxel-social-login-bypass-cve-2026-8508","description":"Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 01:03:29","updated_at":"2026-08-17 02:45:10","pushed_at":"2026-08-17 02:45:02","inserted_at":"2026-08-17 04:37:11"},{"id":"1336113406","cve_id":"CVE-2026-6837","name":"CVE-2026-6837-zyxel-export-cgi-command-injection","owner":"minanagehsalalma","full_name":"minanagehsalalma\/CVE-2026-6837-zyxel-export-cgi-command-injection","html_url":"https:\/\/github.com\/minanagehsalalma\/CVE-2026-6837-zyxel-export-cgi-command-injection","description":"Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-17 01:03:03","updated_at":"2026-08-17 02:45:08","pushed_at":"2026-08-17 02:45:00","inserted_at":"2026-08-17 04:37:11"},{"id":"1336056384","cve_id":"CVE-2025-55182","name":"Security_incident_report","owner":"kevin9480","full_name":"kevin9480\/Security_incident_report","html_url":"https:\/\/github.com\/kevin9480\/Security_incident_report","description":"React2Shell(CVE-2025-55182) \ucde8\uc57d\uc810 \uae30\ubc18 \uce68\ud574 \uc2dc\ub098\ub9ac\uc624\ub97c \uc7ac\ud604\ud558\uace0, Wazuh\/Sysmon\/Coraza WAF \ub85c\uadf8\ub85c \uce68\ud574\uc0ac\uace0\ub97c \ubd84\uc11d\u00b7\ub300\uc751\ud55c DFIR \ud504\ub85c\uc81d\ud2b8","stargazers_count":"0","vuln_description":"A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.","created_at":"2026-08-17 00:05:22","updated_at":"2026-08-17 02:53:04","pushed_at":"2026-08-17 02:13:11","inserted_at":"2026-08-17 04:37:10"},{"id":"1336028579","cve_id":"CVE-2026-43499","name":"root-my-s9280","owner":"NanoTurtle1145","full_name":"NanoTurtle1145\/root-my-s9280","html_url":"https:\/\/github.com\/NanoTurtle1145\/root-my-s9280","description":"Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China \/ Hong Kong SAR \/ Taiwan))","stargazers_count":"2","vuln_description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]","created_at":"2026-08-16 23:37:06","updated_at":"2026-08-17 01:37:32","pushed_at":"2026-08-17 01:36:39","inserted_at":"2026-08-17 04:37:11"},{"id":"1336012564","cve_id":"CVE-2026-64638","name":"xss2shell-check","owner":"SanaullahAmanullah","full_name":"SanaullahAmanullah\/xss2shell-check","html_url":"https:\/\/github.com\/SanaullahAmanullah\/xss2shell-check","description":"Non-destructive detector for CVE-2026-64638 (XSS2Shell) \u2014 WordPress pre-auth XSS reflection primitive","stargazers_count":"0","vuln_description":null,"created_at":"2026-08-16 23:23:06","updated_at":"2026-08-16 23:31:52","pushed_at":"2026-08-16 23:30:47","inserted_at":"2026-08-17 04:37:11"}]}