momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9302 条情报 漏洞监控 5521 / 网安开源项目 3781
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Ibrahim-Sartawi/CVE-2026-26718
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CS...
Ibrahim-Sartawi/CVE-2026-26719
A stored Cross‑Site Scripting vulnerability exists in xxl-job-admin JobInfoController.java where the addressList parameter accepts unsanitized URL‑encoded JavaScript. The payload is stored and later executed in users’ br...
dennywise/CVE-2026-51833-Public-Disclosure
CVE-2026-51833 Advisory
JoinChang/ghostlock-oneplus
GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader | topics: android, coloros, ghostlock, kernelsu, oneplus, root | language: C
JoinChang/ghostlock
GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader | topics: android, coloros, ghostlock, kernelsu, oneplus, root | language: C
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For ...
xianwan1314/CVE-2026-43499-Poc-Analysis
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-43499
本次个人漏洞研究进展成果 | language: C
oscerd/CVE-2026-46584
Reproducer for CVE-2026-46584: Apache Camel camel-mail mail.smtp.* header injection enabling credential theft via on-path SOCKS interception (fixed in 4.14.8/4.18.3/4.21.0) | topics: apache-camel, cve, proof-of-concept, ...
MadExploits/ninja-form-exploit
CVE-2026-0740 | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
t84RT/Lock-Crab-File-Encryption-Decryption-Tool
**锁蟹文件加密解密工具** 是一款轻量级、跨平台的桌面安全工具,基于 **AES-256 (Fernet)** 加密算法,为工程师、设计师及普通用户提供快速、可靠的文件加密与解密服务。 | language: Python | stars: 0 | forks: 0 | updated 2026-07-24T09:45:41Z | pushed 2026-07-24T09:45:00Z
anonymous99-Rise/github_monitor
实时监控github上新增的cve、自定义关键词、安全工具更新、大佬仓库监控,并多渠道推送通知 | language: HTML | stars: 1 | forks: 2 | updated 2026-09-09T15:31:40Z | pushed 2026-09-09T15:23:30Z | homepage: https://anonymous99-rise.github.io/github_monitor/
shrektan/ai-model-ids
The canonical developer reference for AI model IDs. One searchable page with copy-paste ready model strings from OpenAI, Anthropic, Google, Mistral, DeepSeek, xAI, and more. Updated daily via GitHub Actions. JSON API inc...
基于大语言模型的智能研发效能助手。深度解析需求文档,精准识别逻辑漏洞;多维度生成测试用例,提升用例设计效率;构建可复用的测试知识库,将个人经验转化为团队资产。赋能 QA 与 PM,实现质量保障智能化。
创建者: xiaozhi86 基于大语言模型的智能研发效能助手。深度解析需求文档,精准识别逻辑漏洞;多维度生成测试用例,提升用例设计效率;构建可复用的测试知识库,将个人经验转化为团队资产。赋能 QA 与 PM,实现质量保障智能化。
一款基于Web的终端连接软件,适合内网穿透、账户管理和多用户使用
创建者: CJ-Chen 一款基于Web的终端连接软件,适合内网穿透、账户管理和多用户使用
本次个人漏洞研究进展成果
创建者: qsvggff-spec 本次个人漏洞研究进展成果
jingl网络安全扫描器,规则主体明显以 Java/Spring/Jalor为主,兼顾多种扫描SKILL.
创建者: N1ght-Awe jingl网络安全扫描器,规则主体明显以 Java/Spring/Jalor为主,兼顾多种扫描SKILL.
多云 AK/SK 后渗透框架 | 授权安全评估专用。Plan-first 受控运维、RAM/实例/数据库操作、对象存储、风险评分、SQLite 快照。仅限授权测试。
创建者: Gumayusi428 多云 AK/SK 后渗透框架 | 授权安全评估专用。Plan-first 受控运维、RAM/实例/数据库操作、对象存储、风险评分、SQLite 快照。仅限授权测试。
融合pentestAGI以及Strix的漏洞自动挖掘平台
创建者: first2233 融合pentestAGI以及Strix的漏洞自动挖掘平台
云安全漏洞挖掘与利用 Skill。S3 桶爆破枚举、公开桶敏感文件发现、SSRF→IMDS 凭证窃取探测、K8s 未授权访问检测、容器逃逸条件识别、 AK/SK 凭证验证与权限枚举、存储桶供应链攻击利用。
创建者: mouren101 云安全漏洞挖掘与利用 Skill。S3 桶爆破枚举、公开桶敏感文件发现、SSRF→IMDS 凭证窃取探测、K8s 未授权访问检测、容器逃逸条件识别、 AK/SK 凭证验证与权限枚举、存储桶供应链攻击利用。