momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 4744 条情报 漏洞监控 2963 / 网安开源项目 1546 / 威胁情报 235

漏洞监控

来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。

2963总量

网安开源项目

优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。

1546总量

威胁情报

来自 360、奇安信、斗象等官方站点的公开情报聚合。

235总量
0xgh057r3c0n/CVE-2026-0740
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload | language: Python
Andyyyyuan/DomainPenetrationTools
集合一些域渗透的工具 | language: Python | stars: 0 | forks: 0 | updated 2026-04-17T09:07:53Z | pushed 2026-04-17T09:07:48Z
Multiple Vulnerabilities in Cisco Catalyst SD-WAN Products Could Allow for Authentication Bypass
<p>Multiple vulnerabilities have been discovered in Cisco Catalyst SD-WAN products, the most severe of which could allow for authentication bypass. Cisco Catalyst SD-WAN (formerly Viptela) is a secure, cloud-delivered so...
pjt3591oo/CVE-2026-40175-poc
language: JavaScript
EdinLyle/Caramel-Pudding
焦糖布丁(Caramel Pudding)是一款专为 OpenClaw AI Gateway 打造的安全基线与漏洞检测工具,集成 12 大核心检测模块(配置安全、技能包安全、端口暴露、认证口令、供应链、主机安全、密钥泄露、反代配置、运行时检查、漏洞扫描、安全基线、数据泄露防护)与龙虾安全守卫功能(安全审计、自动加固、技能扫描、文件完整性、隐私检查、行为检测),支持 Ollama 本地模型与云端大模型双模式 AI 深度审计,提供一键自动修...
A Vulnerability in Dell RecoverPoint for Virtual Machines Could Allow for Arbitrary Code Execution
<p>A vulnerability has been discovered in Dell RecoverPoint for Virtual Machines which could allow for arbitrary code execution. Dell RecoverPoint for Virtual Machines is an enterprise-grade solution for VMware Virtual M...
SpdyStream: DOS on CRI
L1nf3ng/WHorse
WHorse是一款现代化的、性能更快的Web漏洞扫描器,目前正在使用rust重新开发。 | topics: vulnerability-scanners | language: Python | stars: 5 | forks: 2 | updated 2025-12-31T01:50:13Z | pushed 2026-03-26T17:01:55Z
A Vulnerability in Google Chrome Could Allow for Arbitrary Code Execution
<p>A vulnerability has been discovered in Google Chrome which could allow for arbitrary code execution. Successful exploitation of the vulnerability could allow for arbitrary code execution in the context of the logged o...
cipher1x1/CVE-2026-29000
Proof of Concept for CVE-2026-29000, a vulnerability in pac4j-jwt | language: Python
ctkqiang/CVE-Exploits
一个收集各种CVE漏洞的PoC(概念验证)或Exploit(漏洞利用)工具的仓库。旨在为安全研究、渗透测试提供参考和便利。 | language: Go | stars: 4 | forks: 0 | updated 2026-03-26T13:09:28Z | pushed 2026-03-26T13:09:23Z
喜迎新春,马跃新程!长亭科技与您共同守护网络安全!
喜迎新春!马跃新程!
masterwok/PoC-CVE-2026-21858
Proof-of-concept exploit for CVE-2026-21858 (ni8mare) impacting n8n versions < 1.121.0 | language: Python
RasAlGhul-1/PrivHelper
PrivHelper 是一个面向渗透测试/OSCP场景的轻量级提权辅助面板,用于统一管理本地工具集(tools 目录),并提供一个 HTTP 文件服务器给目标机下载,同时在 Web 面板中展示每个工具的使用说明与下载直链(点击即可复制)。 | language: Shell | stars: 5 | forks: 0 | updated 2026-04-04T17:30:40Z | pushed 2026-04-04T17:30:36Z
每周高级威胁情报解读(2026.02.06~02.12)
Prince of Persia 组织最新攻击动向分析;研究人员发现疑似APT-Q-27组织针对金融机构发起多阶段攻击;APT-C-28 利用 MiradorShell 发起网络攻击的安全预警;Transparent Tribe组织瞄准印度初创企业传播Crimson RAT
r3verii/CVE-2026-33555
One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users on a completely different frontend protocol. | language: Python
Andyyyyuan/CVE-Poc
存放一些渗透打靶中积累的CVE-poc | language: Python | stars: 0 | forks: 0 | updated 2026-03-26T09:08:44Z | pushed 2026-03-26T09:08:30Z
每周勒索威胁摘要
1.Qilin勒索团伙公布了新的受害者 2.Play勒索团伙公布新的受害公司 3.Spacebears勒索团伙公布新的受害公司
menevarad007/CVE-2026-37750
CVE-2026-37750 — School Management System 1.0 - Reflected XSS | language: Python
smallcat9612/ai-pentest-bot
基于ai训练的渗透模型+智能体,支持内网渗透。 | stars: 0 | forks: 0 | updated 2026-04-06T11:05:55Z | pushed 2026-04-06T11:05:50Z
已修复 | 微信Linux版本远程命令执行漏洞
立即查看详情 →
menevarad007/CVE-2026-37749
CVE-2026-37749 — CodeAstro Simple Attendance Management System 1.0 - SQL Injection | language: Python
Duckweed-yhb/CTF-Practice
存放哈尔滨工业大学(深圳)《网络安全攻防竞赛实践》课程实验WP、CTF比赛解题WriteUp、解题脚本及学习笔记,持续更新。 | stars: 0 | forks: 0 | updated 2026-03-25T21:27:53Z | pushed 2026-03-25T21:27:50Z
云上安全态势报告-2026年1月
云上安全态势报告-2026年1月
menevarad007/CVE-2026-37748
Visitor Management System 1.0 - Unrestricted File Upload → RCE (CVE-2026-37748) | language: Python
lanyasheng/skill-evaluator
评估和提升其他 Skill 的能力,提供基准测试、红队测试和改进建议 | language: Python | stars: 1 | forks: 0 | updated 2026-03-25T13:13:48Z | pushed 2026-03-25T12:42:22Z
长亭战略投资薮猫:AI + 终端数据安全的“顶配”合作
强势围观!
z3r0h3ro/CVE-2026-33824
Windows IKEv2 Double-Free RCE
musenli/LSB_steganography
可实现将base64加密的数据往png图片中隐写;从png图片中提取base64加密数据并保存,或者提取base64加密数据并执行。适用于CTF或者渗透测试的小工具 | language: Python | stars: 0 | forks: 0 | updated 2026-03-25T10:50:22Z | pushed 2026-03-25T02:01:07Z
Multiple Vulnerabilities in Ivanti Endpoint Manager Could Allow for Authentication Bypass
<p>Multiple vulnerabilities have been discovered in Ivanti Endpoint Manager, the most severe of which could allow for authentication bypass. Ivanti Endpoint Manager is a client-based unified endpoint management software....