momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9130 条情报 漏洞监控 5435 / 网安开源项目 3695
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
webshellseo8/CVE-2026-50522-Proof-of-Concept
webshellseo8/CVE-2026-61511-POC
MalHyuk/CVE-2026-59243
CVE-2026-59243 — Apache Airflow FAB Auth Manager JWT signature bypass (embargoed until Apache advisory) | topics: airflow, authentication-bypass, cve, jwt, oauth, security | language: Python
4D4J/objdump-Out-Of-Bounds-write
Proof of Concept (PoC) demonstrating the CVE-2026-18220, an out-of-bounds (OOB) write vulnerability in the DLX ELF backend of GNU binutils (specifically triggered via `objdump -g`) | language: Python
sandraschi/copy-fail-mcp
CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP | topics: clipboard, copy, fastmcp, mcp, python | language: Python
afertar/CVE-2026-16475-PoC
This is the official repo with the PoC of the CVE-2026-16475, LFI in OCSinventory 2.12.4. | language: Python
mdvpat/CVE-2026-52832-PoC-exploit-nuclio-dashboard
Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so ../../../../tmp/x.txt:handler escapes the build tempdir via path.Join, letting an attacker write ar...
mdvpat/CVE-2026-52832-PoC-exploit-nuclei-dashboard
Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so ../../../../tmp/x.txt:handler escapes the build tempdir via path.Join, letting an attacker write ar...
tc4dy/CVE-2026-61511-PoC-Exploit
CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full toolkit: reverse shell, proxy, persistence, webshell, database operations, fir...
HORKimhab/CVE-2026-33718
CVE-2026-33718
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
lxekslvjwu/McqimyYMuQ
【Java计算机毕业设计分享】基于Jboss的渗透测试管理系统,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-08-05T19:49:44Z | pushed 2026-08-05T19:49:34Z
n6jx7ld0er/TpCsXYkKpF
【Python计算机毕业设计分享】基于Python的Web安全渗透测试系统,MySQL Python开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-08-05T20:26:44Z | pushed 2026-08-05T20:25:08Z
px2ysv789z/njNlvkNbIQ
【Java计算机毕业设计分享】基于Python的后渗透框架设计与实现,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-08-05T22:16:17Z | pushed 2026-08-05T22:15:53Z
xiaoyuhenguai/AuAttack
一个以证据为主的ai自动化渗透测试项目 | language: Lua | stars: 8 | forks: 0 | updated 2026-08-23T18:15:37Z | pushed 2026-08-21T06:08:17Z
IHateTheWorld-LYK/Hemlock
AI Agent + 抓包融合安全测试工具 | 自然语言驱动自主渗透测试 | ReAct 编排引擎 | Tauri + FastAPI | topics: ai-agent, burp-suite, cybersecurity, llm, mitmproxy, offensive-security, penetration-testing, pentesting, security-tools, web-security | langu...
CharlesCNorton/humprobe
Mains-hum forensics for audio and video: grid region, transfer speed, shared lineage, and dating from the 50/60 Hz hum | language: Python | stars: 0 | forks: 0 | updated 2026-08-06T01:29:03Z | pushed 2026-08-06T01:28:59Z
luojiyin1987/npm-supply-chain-incident-response
Investigate and contain malicious npm package releases with version-scoped triage, tarball forensics, credential analysis, and safe deprecation. | topics: agent-skil, devsecops, incident-response, npm-security, security-...
78778443/QingScan
一个漏洞扫描器粘合剂,添加目标后30款工具自动调用;支持 web扫描、系统扫描、子域名收集、目录扫描、主机扫描、主机发现、组件识别、URL爬虫、XRAY扫描、AWVS自动扫描、POC批量验证,SSH批量测试、vulmap。 | language: PHP | stars: 1830 | forks: 289 | updated 2026-09-07T05:55:06Z | pushed 2026-08-04T12:31:01Z
boom5497/GDbEDbHP
【Python计算机毕业设计分享】基于Python的web渗透漏洞扫描工具研究与应用,MySQL Python开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-08-04T19:39:11Z | pushed 2026-08-04T19:35:58Z
px2ysv789z/vNKcduoIWW
【Java计算机毕业设计分享】基于SSM的漏洞扫描器管理系统,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-08-04T22:32:11Z | pushed 2026-08-04T22:31:00Z