momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9292 条情报 漏洞监控 5517 / 网安开源项目 3775
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
codeb0ssx/CVE-2026-15583-PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research. | topics: codeb0ss, cve-2026-15583, cve-2026-15583-poc, grafana, realcodeb0ss, thecodeb0ss | language: Python
codeb0ssx/CVE-2026-46442-PoC
Academic proof-of-concept demonstrating CVE-2026-46442 for authorized security research. | topics: codeb0ss, cve-2026-46442, cve-2026-46442-poc, flowise-ai, realcodeb0ss, thecodeb0ss | language: Python | homepage: https:...
CerberusMrXi/WordPress-KeepInMind-CVE-2026-9271-Exploit
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, a...
MiaPatsune/cve-2026-43499
language: HTML
bekwiner/cve-2026-47777
oscerd/CVE-2026-48204
Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete files) from an unauthenticated HTTP request (fixed in 4.14.8/4.18.3/4.21.0...
Industri4l-H3ll-Xpl0it3rs/CVE-2026-33017-Langflow-RCE
CVE-2026-33017 Exploit | by infrar3d | topics: exploit | language: Python
karollooool/Porting-CVE-2026-31431-Copy-Fail-to-a-Constrained-Java-Runner
CVE-2026-31431 (copy.fail) — adapted for constrained Java execution environments via FFM syscall layer + javac annotation processor delivery | topics: af-alg, copyfail, cve-2026-31431, java, linux-kernel, lpe, page-cache...
jaf0rk/CVE-2026-14431
language: JavaScript
oscerd/CVE-2026-48203
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0) | topics: apache-came...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
RasAlGhul-1/PrivHelper
PrivHelper 是一个面向渗透测试/OSCP场景的轻量级提权辅助面板,用于统一管理本地工具集(tools 目录),并提供一个 HTTP 文件服务器给目标机下载,同时在 Web 面板中展示每个工具的使用说明与下载直链(点击即可复制)。 | language: Shell | stars: 5 | forks: 0 | updated 2026-07-19T15:03:38Z | pushed 2026-07-19T15:03:31Z
Zoot-running/Fedai
基于Divan构建的自动化黑盒渗透工具,发掘网站的漏洞,还能做做CTF。 | stars: 0 | forks: 0 | updated 2026-07-19T20:39:37Z | pushed 2026-07-19T20:39:34Z
caichao061025-lang/Quench
淬火 (Quench) - 轻量级 Webshell 管理工具,专为授权渗透测试、CTF 竞赛和安全教学而设计 | language: Python | stars: 5 | forks: 0 | updated 2026-07-20T07:37:29Z | pushed 2026-07-17T16:12:48Z
ClumsyChou/Kali
使用Kali Linux进行渗透测试基础训练 | stars: 0 | forks: 0 | updated 2026-07-20T08:15:26Z | pushed 2026-07-20T08:14:53Z
crabin/AutoPentest-XL
AutoPentest-XL 是一个基于 LangGraph 多 Agent 编排的自主渗透测试平台,通过增强型 RAG 和严格安全围栏实现从初始侦察到 Root 提权的全流程自动化。 | language: Python | stars: 4 | forks: 1 | updated 2026-07-21T07:29:10Z | pushed 2026-07-21T07:28:41Z
a5155613/Termux-SecBox
安卓离线安全渗透工具箱 | language: Python | stars: 2 | forks: 0 | updated 2026-07-21T13:40:50Z | pushed 2026-07-18T17:24:49Z
CharlieYin05/Flask_TravelBlog_v2.0
本项目脱胎于cits3403-project。本项目用于TravelBlog的维护与渗透测试 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-07-19T04:42:20Z | pushed 2026-07-21T15:42:38Z | homepage: https://travelblog.cy-server.com
Maple0208/Paradox
Paradox是一个面向Web渗透与代码审计的企业管理系统靶场,重点训练逻辑漏洞,同时包含注入、XSS、文件上传等常见漏洞场景。 | language: HTML | stars: 24 | forks: 0 | updated 2026-07-22T06:04:13Z | pushed 2026-07-21T14:43:57Z
nmcp0114/Aipentest-burp
burpsuite的AI渗透插件demo | language: Java | stars: 0 | forks: 0 | updated 2026-07-27T00:47:21Z | pushed 2026-07-27T00:47:18Z
WAjkl/pentest-gui
16 个渗透测试工具的集成 GUI 平台,一键安装,开箱即用 | topics: chinese, nuclei, pentest, python, security-tools, thinker, vulnerability-scanner | language: Python | stars: 1 | forks: 0 | updated 2026-07-22T09:54:15Z | pushed 2026-07-17T19:38:...