momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9099 条情报 漏洞监控 5418 / 网安开源项目 3681
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
martincifu/YellowKey-Bitlocker-CVE-2026-45585
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. ...
0xmrma/CVE-2026-5061
Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the link between those operations turned an in-sandbox file reference into ...
0xmrma/CVE-2026-14361
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
envincion1991-cmyk/CVE-2026-51954
Vulnerability Research
0xBlackash/CVE-2026-64531
CVE-2026-64531 | language: Python
7h30th3r0n3/CVE-2026-53625-GLPI-PoC
GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full control of any Super-Admin account through REST API authtype manipulatio...
aj2108/CVE-2026-8237
CVE-2026-8237 is an Insecure Direct Object Reference (IDOR) vulnerability caused by missing authorization checks in Concrete CMS 9.5.0 and earlier.
MinhHK68/CVE-2026-13158
topics: arbitrary-file-upload, bugbounty, cve, cve-2026-13158, huynh-kien-minh, infosec, poc, rce, security-advisory, wordpress | language: HTML | homepage: https://minhhk.web.app/#cves
Popy21/security-research
Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP
MinhHK68/CVE-2026-13157
language: HTML
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Aether 是一套基于大模型的自主渗透测试执行系统,通过 Planner–Executor–Reflector(P-E-R)多智能体协作闭环,将渗透测试从"人工逐条下发指令"推进到"任务级自主规划、并行执行、证据驱动收敛、可人工干预"的自动化阶段。 本仓库为 AetherAgent 开放展示仓库:公开设计文档与发行产物,不包含源代码与构建流程。
创建者: JiuZero Aether 是一套基于大模型的自主渗透测试执行系统,通过 Planner–Executor–Reflector(P-E-R)多智能体协作闭环,将渗透测试从"人工逐条下发指令"推进到"任务级自主规划、并行执行、证据驱动收敛、可人工干预"的自动化阶段。 本仓库为 AetherAgent 开放展示仓库:公开设计文档与发行产物,不包含源代码与构建流程。
Query IoT firmware CVEs by device/component and auto-download PoCs — an MCP server for AI agents. 物联网固件漏洞情报 + PoC 自动下载的 MCP 工具,供 AI agent 直接调用。
创建者: kaf6rim Query IoT firmware CVEs by device/component and auto-download PoCs — an MCP server for AI agents. 物联网固件漏洞情报 + PoC 自动下载的 MCP 工具,供 AI agent 直接调用。
SpyProbe 通用逆向探测/抓包工作台(LSPosed 模块):SSL绕过+OkHttp抓包+URL捕捉+加密记录+Log拦截+函数探测+返回值劫持+SQLite记录 | 不可商用
创建者: kiminbaek SpyProbe 通用逆向探测/抓包工作台(LSPosed 模块):SSL绕过+OkHttp抓包+URL捕捉+加密记录+Log拦截+函数探测+返回值劫持+SQLite记录 | 不可商用
通过 http mcp sever 服务,发送消息通知, 可以绕过 chatgpt 的定时任务的权限限制
创建者: sorry510 通过 http mcp sever 服务,发送消息通知, 可以绕过 chatgpt 的定时任务的权限限制
WAF绕过样本产出实践
创建者: Kittyyyyhyh WAF绕过样本产出实践
Binary Ninja逆向破解:许可证字符串定位、条件跳转分析、PE补丁绕过
创建者: NothingFumo Binary Ninja逆向破解:许可证字符串定位、条件跳转分析、PE补丁绕过
Lightweight Webshell panel
创建者: yumao233 Lightweight Webshell panel
Gito AI 代码审查演示 - 故意包含安全漏洞的示例代码
创建者: zurheidegenetthx379-ui Gito AI 代码审查演示 - 故意包含安全漏洞的示例代码
红队部门 Hermes profile 发行版:授权渗透测试/情报/利用验证/报告
创建者: zyj010216y 红队部门 Hermes profile 发行版:授权渗透测试/情报/利用验证/报告
面向青少年的网络安全纵深防御互动课堂
创建者: flyingbluegithub 面向青少年的网络安全纵深防御互动课堂