momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9102 条情报 漏洞监控 5420 / 网安开源项目 3682
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
TeamN4C/SG-2026-0013
CVE-2026-31431 Copy Fail PoC and exploit | language: C
AadityaKandel/CVE-2026-43284
This is the compiled version. This is not my program though. This is only for directly downloading the compiled version in labs where there is no gcc
aj2108/CVE-2026-8347
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, a...
KrakenEU/CVE-2026-54121-CertiGhost
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC | language: Python
fazilbaig1/CVE-2026-16723
This is N-day patch we releasing by testing our model capabilities | language: Java
LuZe0y/pd2425-cve-2026-43499-config
language: C
nafiez/Metasploit-CVE-2026-54121-Certighost
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-cont...
Chromium: CVE-2026-17719 Use after free in Input
<p>This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17723 Use after free in Media
<p>This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17752 Use after free in Views
<p>This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
一款根据目标单位名称和备案域名ip进行资产信息收集工具
创建者: keiokr 一款根据目标单位名称和备案域名ip进行资产信息收集工具
内网资产信息收集
创建者: keiokr 内网资产信息收集
一个轻量的 PHP 一句话 Webshell 连接与管理工具,纯 Python 标准库实现,无需安装任何依赖。 面向授权渗透测试与靶场研究场景,除基础的命令执行 / 文件传输外,内置 PHP-FPM bypass 能力:在目标 disable_functions 禁掉全部命令执行函数时,通过直连本机 FPM socket 加载恶意扩展实现绕过
创建者: xy200303 一个轻量的 PHP 一句话 Webshell 连接与管理工具,纯 Python 标准库实现,无需安装任何依赖。 面向授权渗透测试与靶场研究场景,除基础的命令执行 / 文件传输外,内置 PHP-FPM bypass 能力:在目标 disable_functions 禁掉全部命令执行函数时,通过直连本机 FPM socket 加载恶意扩展实现绕过
覆盖移动端应急响应、溯源分析、证据提取和取证研究
创建者: SecLeap 覆盖移动端应急响应、溯源分析、证据提取和取证研究
zhihua-tech/zhuatech-agentsec
知华科技 AgentSec 社区源码版|Agent 红队测试与发布门禁 | language: Java | stars: 2 | forks: 0 | updated 2026-08-22T02:32:31Z | pushed 2026-08-22T02:32:27Z
sorabug/Net-Loader
Net-Loader 是一个授权红队用途的 .NET 载荷生成工具 | language: C# | stars: 4 | forks: 0 | updated 2026-08-13T12:45:34Z | pushed 2026-08-01T06:57:56Z
liucy-666/NCRT
一个集成化越狱红队测试平台 | language: Python | stars: 3 | forks: 0 | updated 2026-08-05T11:43:33Z | pushed 2026-07-29T11:50:17Z
Lirunyi-123/legal-document-desensitizer
中国法律文书脱敏工具:20+类中国法律实体(身份证GB11643/信用代码GB32100/案号/律师执业证号/车牌等)→语义占位符,AES加密映射表一键无损还原,红队评测量化,本地优先、LLM可选(Ollama/云端API),面向中国律师。 | topics: chinese, data-privacy, desensitization, legal-documents, legal-tech, llm, nlp, pii, priva...
AKArrok/McPwn
通用 MCP 红队 agent:对准任意 MCP server 的 SSE 端点,自动完成侦察→假设→攻击→验证→报告,产出可重放 PoC。DVMCP 只是回归 fixture,不是产品目标。 | language: Python | stars: 0 | forks: 0 | updated 2026-08-07T02:52:14Z | pushed 2026-08-30T14:22:59Z
0rangec3t/Black-cat
Claude Code RedTeam Skill — Hypothesis-Driven Cognitive Architecture。一个假设-证据驱动的红队skill | topics: pentest, pentest-tools, red-team | language: Python | stars: 306 | forks: 36 | updated 2026-09-02T02:22:36Z | pushed 2026-0...