momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9238 条情报 漏洞监控 5506 / 网安开源项目 3732
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
oscerd/CVE-2026-49099
PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and overrides the producer's configured SOQL (SOQL injection / broken access co...
securelayer7/WordPresShell
Pre-auth RCE PoC for CVE-2026-63030 / CVE-2026-60137 (WordPress core) | topics: cve-2026-60137, cve-2026-63030, poc, rce, wordpress | language: Python
dinosn/CVE-2026-25243-debugfree
language: Python
Colere-Sys/wp2shell-poc
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030 | language: Python
oscerd/CVE-2026-48206
Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue operations with the endpoint's service-account credentials (fixed in 4.14.8/4.1...
Dynamo2k1/CVE-2026-33017
language: Python
NULL200OK/WP2Shell
WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, allowing unauthenticated attackers to execute arbitrary SQL que...
gagaltotal/CVE-2026-42533-nginx
CVE-2026-42533 Nginx | topics: cve, cve-2026-42533, cve-2026-42533-poc, cve-2026-42533-scanner, go, golang, golang-cli, nginx, nginx-server | language: Go
Max78000/CVE-2026-0560-lollms
Test server and PoC
Max78000/CVE-2026-27641-Flask-Reuploaded
PoC and test server | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
AI代码审计多Agent系统
创建者: IceFoxH AI代码审计多Agent系统
汽车渗透门户
创建者: jingminglong 汽车渗透门户
AgentZero2002/LLMAlignment
THU大语言模型 Part III: 对齐与后训练 | SFT/RLHF/DPO/ConstitutionalAI/安全红队/评估/LoRA/偏好数据/对齐税/Superalignment | 16章Python+NumPy | language: Python | stars: 1 | forks: 0 | updated 2026-08-23T16:20:21Z | pushed 2026-07-27T08:54:52Z
d558mju7m2/mUPjhzRyTW
【Java计算机毕业设计分享】基于SpringBoot+Vue浏览器攻防平台,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-07-26T18:26:51Z | pushed 2026-07-26T18:26:48Z
AIJobpublic/hackingtool-defense-guide
🛡️ 從攻擊者角度學習 190+ 駭客工具,強化你的網站防禦能力 | HackingTool 攻防教學 | language: HTML | stars: 0 | forks: 0 | updated 2026-07-27T10:28:19Z | pushed 2026-07-27T10:27:33Z
b9767te1al/XFfbsJpU
【Java计算机毕业设计分享】基于SpringBoot+Vue浏览器攻防平台,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-07-27T14:58:58Z | pushed 2026-07-27T14:57:52Z
YunSeeTeam/YunSeeTeam.github.io
YunSee CTF 战队官网 — 攻防对抗 / 漏洞研究 / 安全竞赛。纯静态,零构建零依赖。 | language: CSS | stars: 0 | forks: 0 | updated 2026-08-26T01:59:03Z | pushed 2026-08-26T01:59:00Z
将时间维度暂留视觉 + 物理拖拽迷宫 + 语义/算力蜜罐三者结合的创新性反 AI 验证码开源组件
创建者: Z-V-I 将时间维度暂留视觉 + 物理拖拽迷宫 + 语义/算力蜜罐三者结合的创新性反 AI 验证码开源组件
燕云十六声兑换码批量自动填写工具。纯 Python 标准库,绕过输入法拦截,无需 OCR 即可判断兑换结果。
创建者: yunyi-zhao 燕云十六声兑换码批量自动填写工具。纯 Python 标准库,绕过输入法拦截,无需 OCR 即可判断兑换结果。
fastjson2 ≤ 2.0.62 利用多态反序列化(ObjectReaderSeeAlso)+ URLClassLoader.findClass 点号转斜杠替换,绕过 AutoType 白名单及 JDK ClassLoader.checkName,实现远程代码执行。
创建者: heart147 fastjson2 ≤ 2.0.62 利用多态反序列化(ObjectReaderSeeAlso)+ URLClassLoader.findClass 点号转斜杠替换,绕过 AutoType 白名单及 JDK ClassLoader.checkName,实现远程代码执行。