momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 4748 条情报 漏洞监控 2967 / 网安开源项目 1546 / 威胁情报 235

漏洞监控

来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。

2967总量

网安开源项目

优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。

1546总量

威胁情报

来自 360、奇安信、斗象等官方站点的公开情报聚合。

235总量
menevarad007/CVE-2026-37750
CVE-2026-37750 — School Management System 1.0 - Reflected XSS | language: Python
cliayn/Decrypt_Html
前端的渗透测试常用的加解密算法的平台 | topics: aes, decryption, encryption, html, javascript, js, rsa, sm2, sm3, sm4 | language: HTML | stars: 0 | forks: 0 | updated 2026-04-27T14:44:49Z | pushed 2026-04-27T14:43:43Z | homepage: https://c...
Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution
<p>Multiple vulnerabilities have been discovered in Fortinet products, the most severe of which could allow for arbitrary code execution.</p><p><br></p><ul><li>FortiAuthenticator is a centralized identity and access mana...
menevarad007/CVE-2026-37749
CVE-2026-37749 — CodeAstro Simple Attendance Management System 1.0 - SQL Injection | language: Python
Odinfreed/learn
这是渗透的开始 | language: HTML | stars: 0 | forks: 0 | updated 2026-03-24T17:08:20Z | pushed 2026-03-24T17:08:16Z
每日安全动态推送(26/2/9)
入侵SonicWall并利用已撤销EnCase驱动绕过EDR;Opus 4.6 的 500 个 0day,对我们来说意味着什么;Android Pixel 9 的零点击漏洞利用链全解析
menevarad007/CVE-2026-37748
Visitor Management System 1.0 - Unrestricted File Upload → RCE (CVE-2026-37748) | language: Python
keven1z/simpleIAST
simpleIAST- 基于污点追踪的灰盒漏洞扫描工具。 | topics: agent, iast, java, security-audit, security-tools | language: Java | stars: 101 | forks: 10 | updated 2026-03-05T08:32:13Z | pushed 2026-03-24T12:56:40Z
AI+安全=?长亭科技的2025高光回溯
强势围观
z3r0h3ro/CVE-2026-33824
Windows IKEv2 Double-Free RCE
josephway/claude-code-mirror-analysis
Mirror Thinking / Contrarian Analysis Skill for Claude Code - 投资决策的逆向思维红队测试 | stars: 0 | forks: 0 | updated 2026-03-24T09:42:00Z | pushed 2026-03-24T09:41:56Z
奇安信获“一级支撑单位”和“特殊贡献奖”
奇安信荣膺 “2025年度突一级支撑单位” 称号,并荣获“2025年度特殊贡献奖”!
keraattin/CVE-2026-22679
Critical RCE vulnerability (CVSS 9.3) in Weaver E-cology platform versions prior to build 20260312. Unauthenticated remote code execution via exposed debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method. Com...
wuziqin1124-code/ClawScout
ClawScout 是一款专为 OpenClaw 生态系统打造的轻量级安全侦察与漏洞扫描工具 | stars: 0 | forks: 0 | updated 2026-03-24T02:17:36Z | pushed 2026-03-24T02:17:33Z
每周高级威胁情报解读(2026.01.30~02.05)
深入分析APT42组织的PowerShell后门程序TAMECAT;追踪 Lazarus 更先进的 OtterCookie 恶意软件;APT28 利用 CVE-2026-21509 和云 C2 基础设施发起多阶段攻击活动;Lazarus 利用 Teams 会议进行 macOS 凭证窃取
venom203020/CVE-2026-5059-poc
poc CVE-2026-5059 in aws-mcp-server
cyber-sorted/cybersorted-mcp
CyberSorted MCP Server — AI-powered security tools via any MCP client | language: Python | stars: 0 | forks: 0 | updated 2026-03-23T21:07:49Z | pushed 2026-03-23T21:07:43Z
每周勒索威胁摘要
1. Qilin勒索团伙公布了新的受害者 2. Play勒索团伙公布新的受害公司 3. Akira勒索团伙公布新的受害公司
seokjohn/CVE-2026-1880
ASUS DriverHub Driver Update Process TOCTOU Vulnerability Leading to LPE | language: C++
akikrasic/Security-tool-in-Kotlin-Proxy-Fuzzer...
language: Kotlin | stars: 1 | forks: 0 | updated 2026-03-23T20:43:04Z | pushed 2026-03-23T20:43:00Z
每日安全动态推送(26/2/5)
只要安装了Clawdbot,你的电脑就可以被黑客控制;AI网络爬虫安全白皮书;视觉提示注入攻击可劫持自动驾驶汽车与无人机
helGayhub233/CVE-2026-34486-Tribes
Tribes 协议探测 | language: Python
BeyondTrust/bedrock-keys-security
Security tools and SCPs for AWS Bedrock API keys and the phantom IAM users they create | topics: amazon-bedrock, api-keys, aws, aws-iam, aws-organizations, aws-security, cloud-security, cloudtrail, incident-response, llm...
Threat Level - GUARDED
National Threat Level: Blue (Guarded) This threat level is based on analysis by the Center for Internet Security® (CIS®) Operations, Intelligence, and Services (OIS) department covering the cyber threat landscape for Qua...
EQSTLab/CVE-2026-34220
language: JavaScript
PYatiM/Sec_basic
Repo with basic security tools | language: Python | stars: 0 | forks: 0 | updated 2026-03-23T18:05:54Z | pushed 2026-03-23T18:05:40Z
警惕你的Skills:OpenClaw开源生态skills风险分析
攻击者通过伪造热门插件并上传至ClawHub技能平台,诱导用户安装恶意技能(Skill),形成一类高隐蔽性攻击。这些恶意样本通常伪装为“浏览器助手、社交代理、财经工具”等常见类别,通过仿冒官方页面布局与文件结构,仅在安装脚本中隐藏后门逻辑。
AnggaTechI/Mass-Scanner-CVE-2026-3891
CVE-2026-3891 Mass Scanning | language: Python
xiaotianlou/lan-attack-toolkit
Python LAN security tools: ARP spoofing, network scanning. For educational use only. | language: Python | stars: 0 | forks: 0 | updated 2026-03-23T18:04:31Z | pushed 2026-03-23T18:04:28Z
已复现!大蚂蚁 (BigAnt) 即时通讯系统任意文件上传漏洞
立即查看详情 →