<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>PoC-in-GitHub RSS</title>
    <link>https://poc-in-github.motikan2010.net/</link>
    <description>PoC auto collect from GitHub. Be careful Malware.</description>
    <lastBuildDate>Tue, 18 Aug 2026 02:03:24 +0900</lastBuildDate>

    <item>
        <title>defineid/Revenant</title>
        <link>https://github.com/defineid/Revenant</link>
        <description>[GitHub]CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)</description>
        <pubDate>Tue, 18 Aug 2026 02:03:24 +0900</pubDate>
        <category>CVE-2026-74943</category>
    </item>
    <item>
        <title>defineid/Palimpsest</title>
        <link>https://github.com/defineid/Palimpsest</link>
        <description>[GitHub]CVE-2026-74945 · Uninitialized heap disclosure via a crafted web font (sec-high)</description>
        <pubDate>Tue, 18 Aug 2026 02:03:31 +0900</pubDate>
        <category>CVE-2026-74945</category>
    </item>
    <item>
        <title>defineid/Trespasser</title>
        <link>https://github.com/defineid/Trespasser</link>
        <description>[GitHub]CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender</description>
        <pubDate>Tue, 18 Aug 2026 02:03:37 +0900</pubDate>
        <category>CVE-2026-74970</category>
    </item>
    <item>
        <title>CVE-2026-6765 (2026-04-21) defineid/SkeletonKey</title>
        <link>https://github.com/defineid/SkeletonKey</link>
        <description>Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.<br/>[GitHub]CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox</description>
        <pubDate>Tue, 18 Aug 2026 02:03:44 +0900</pubDate>
        <category>CVE-2026-6765</category>
    </item>
    <item>
        <title>CVE-2025-24071 (2025-03-12) kaIIsyms/CVE-2025-24071</title>
        <link>https://github.com/kaIIsyms/CVE-2025-24071</link>
        <description>Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.<br/>[GitHub]Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak</description>
        <pubDate>Tue, 18 Mar 2025 21:51:35 +0900</pubDate>
        <category>CVE-2025-24071</category>
    </item>
    <item>
        <title>Jvr2022/CVE-2026-40345</title>
        <link>https://github.com/Jvr2022/CVE-2026-40345</link>
        <description>[GitHub]A poc and write-up for CVE-2026-40345</description>
        <pubDate>Mon, 17 Aug 2026 23:06:41 +0900</pubDate>
        <category>CVE-2026-40345</category>
    </item>
    <item>
        <title>CVE-2026-33017 (2026-03-20) l4st98/CVE-2026-33017-FireFlow</title>
        <link>https://github.com/l4st98/CVE-2026-33017-FireFlow</link>
        <description>Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.<br/>[GitHub]CVE-2026-33017, vuln in langflow.</description>
        <pubDate>Tue, 18 Aug 2026 01:12:01 +0900</pubDate>
        <category>CVE-2026-33017</category>
    </item>
    <item>
        <title>defineid/Wildfire</title>
        <link>https://github.com/defineid/Wildfire</link>
        <description>[GitHub]CVE-2026-39154 · Stored XSS in CometChat JS SDK</description>
        <pubDate>Tue, 18 Aug 2026 02:03:52 +0900</pubDate>
        <category>CVE-2026-39154</category>
    </item>
    <item>
        <title>CVE-2026-20079 (2026-03-04) CyberAuth/CVE-2026-20079</title>
        <link>https://github.com/CyberAuth/CVE-2026-20079</link>
        <description>A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
 This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.<br/>[GitHub]Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center.</description>
        <pubDate>Tue, 18 Aug 2026 03:36:35 +0900</pubDate>
        <category>CVE-2026-20079</category>
    </item>
    <item>
        <title>CVE-2025-21479 (2025-06-03) linux-tools/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479</title>
        <link>https://github.com/linux-tools/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479</link>
        <description>Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.<br/>[GitHub]iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** — 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案</description>
        <pubDate>Mon, 17 Aug 2026 23:37:05 +0900</pubDate>
        <category>CVE-2025-21479</category>
    </item>
  </channel>
</rss>