momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9237 条情报 漏洞监控 5505 / 网安开源项目 3732
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
BiiTts/POC-CVE-2026-65971
Proof-of-concept and technical write-up for CVE-2026-65971 — SQL injection via the sortDirection Livewire property in power-components/livewire-powergrid (< 6.10.4) | topics: cve, cve-2026-65971, laravel, livewire, poc, ...
nullRoot-Red/CVE-2026-23744
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+). | language: Python
raphy76/wp2shell-poc-fulljs
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches) | language: JavaScript
karollooool/CVE-2026-50416-writeup-and-poc
CVE-2026-50416: Windows 11 KASLR bypass | topics: cve, cve-2026-50416, information-disclosure, kaslr, kaslr-bypass, kernel, leak, msrc, poc, proof-of-concept, vulnerability, win32k, windows, windows-11, writeup, writeups...
abhinavagarwal07/abhinavagarwal07.github.io
RingWraith: CVE-2026-33150 and CVE-2026-33179 — Use-After-Free and NULL Dereference in libfuse io_uring | language: C
CerberusMrXi/Flowise-CVE-2026-58057-exploit
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file up...
ghapvharmo/gha-lab-a815a82f03-1
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
ghapvharmo/gha-lab-a5c1876997-1
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
4minx/CVE-2026-14266
CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip | language: Python
oscerd/CVE-2026-49099
PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and overrides the producer's configured SOQL (SOQL injection / broken access co...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
面向 AI 生成代码的安全审查 skill,以及一套按「发现难度」而非漏洞类型分档的评测基准方法论
创建者: laolaohe 面向 AI 生成代码的安全审查 skill,以及一套按「发现难度」而非漏洞类型分档的评测基准方法论
个人网络安全渗透测试学习空间 My Cyber Security & Penetration Testing Learning Workspace
创建者: MostimarkQ 个人网络安全渗透测试学习空间 My Cyber Security & Penetration Testing Learning Workspace
跨境宠物帮带信息收集网站交互设计稿
创建者: czc6666 跨境宠物帮带信息收集网站交互设计稿
长城-网络安全智能体
创建者: kafeic 长城-网络安全智能体
通过将文件编码为高密度 64 色彩色图像(RGB 四级编码,6 bits/cell),经截屏传输后解码还原,适合从云桌面向本地电脑绕过审核的文件传输等工作场景。
创建者: Li-Dongcheng 通过将文件编码为高密度 64 色彩色图像(RGB 四级编码,6 bits/cell),经截屏传输后解码还原,适合从云桌面向本地电脑绕过审核的文件传输等工作场景。
最简单的防止SSH暴力破解的脚本
创建者: John10240 最简单的防止SSH暴力破解的脚本
面向授权安全测试的中文网络安全知识库:渗透测试、Tips、Writeups 与 Wiki
创建者: iggcloud 面向授权安全测试的中文网络安全知识库:渗透测试、Tips、Writeups 与 Wiki
用 opencli 把 Boss 直聘上某行业的公司信息抓出来做成线下商务拜访名单。固化 9 个实跑踩坑 + 关键词策略 + 反自动化绕过 + 噪声过滤 + 区域聚类。致敬 opencli —— 闭源应用不能做网页自动化,opencli 开源了这条路。
创建者: yang1996202-cpu 用 opencli 把 Boss 直聘上某行业的公司信息抓出来做成线下商务拜访名单。固化 9 个实跑踩坑 + 关键词策略 + 反自动化绕过 + 噪声过滤 + 区域聚类。致敬 opencli —— 闭源应用不能做网页自动化,opencli 开源了这条路。
证据链驱动的漏洞验证引擎。不是扫描器——每个发现附带一条 curl 命令,终端跑一遍就能复现。
创建者: qianlijaingshan 证据链驱动的漏洞验证引擎。不是扫描器——每个发现附带一条 curl 命令,终端跑一遍就能复现。
这个项目是经过二开的远控软件,支持自定义中继器,修改源代码
创建者: panhouhui 这个项目是经过二开的远控软件,支持自定义中继器,修改源代码