momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9347 条情报 漏洞监控 5550 / 网安开源项目 3797
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
L4V4D0/CVE-2026-29519-Lucee-Reflected-XSS
Proof of Concept for Reflected XSS in Lucee CFML (CVE-2026-29519)
inforcqb/CVE-2026-43499-pja110
language: C
aexdyhaxor/CVE-2026-46331
A Proof of Concept (PoC) exploit for CVE-2026-46331 | language: C
BiiTts/CVE-2026-56423-MISP-deleteSelection-BrokenAccessControl
PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS 8.8) | topics: broken-access-control, cve, cve-2026-56423, cwe-862, ido...
phil-dirt/CVE-2026-41089-LongLogon
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overfl...
pubglite55/oppo-ghostlock
OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation | language: C
BiiTts/CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass
PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1) | topics: apache-apisix, api-gateway, apisix, authentication-bypass, cve, cve-2026-49230, jwe, p...
0x00phantom-hat/CVE-2026-12400-Exploit
language: Python
g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
This repository contains a lab validation report and detection artefacts for DirtyFrag CVE-2026-43284, a Linux local privilege escalation issue related to the XFRM/ESP page-cache write path. The focus is on auditd teleme...
g0thamRabb1t/CVE-2026-50656-rogueplanet-validation
Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection results, risk assessment, and mitigation recommendations.
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
JinChengZ18/resume-grill
An Agent Skill for grilling resumes: feed it one or more resume PDFs and it produces a three-piece interview kit: an interview guide, a printable scorecard, and Q&A attack-defense cards.拷打你简历的 Agent Skill:喂进一份或多份简历 PDF,产...
w-sega/Kafka_Scan_Gui
一个基于 Python Tkinter 的 Kafka 图形化测试工具,用于批量检测 Kafka 目标、获取 topic 列表,可选获取 topic 消息详情,在内网攻防中快速证明kafka成果。 | language: Python | stars: 1 | forks: 0 | updated 2026-07-15T16:45:36Z | pushed 2026-07-10T10:55:17Z
SecLeap/offensive-security
攻防与渗透测试 | stars: 1 | forks: 0 | updated 2026-08-06T07:01:12Z | pushed 2026-07-11T05:16:36Z
SecLeap/security-capability
SecLeap 安全能力建设仓库,聚焦攻防研究、漏洞分析、安全运营、应急响应、威胁检测、自动化工具与知识沉淀。 | language: Batchfile | stars: 1 | forks: 0 | updated 2026-08-10T04:55:22Z | pushed 2026-07-11T05:28:32Z
Mrli8848/kali-china-setup
Kali Linux 全方位配置脚本 - 一键换源/汉化/红蓝队工具链/CTF/无线安全 | language: Shell | stars: 2 | forks: 0 | updated 2026-09-08T13:03:35Z | pushed 2026-07-20T14:02:07Z
gogoore/FMxePQAv
【Java计算机毕业设计分享】基于SpringBoot的云安全攻防训练系统,Java开发 Python开发 深度学习 二次开发 毕业设计 实战项目【附源码、文档报告、代码讲解、部署教程、开题、任务书】 | stars: 1 | forks: 0 | updated 2026-07-08T18:08:59Z | pushed 2026-07-08T18:08:37Z
zfz-725/KubeGuard
精简版 KubeArmor — Kubernetes + eBPF 运行时安全工具 | language: C | stars: 0 | forks: 0 | updated 2026-07-20T08:14:57Z | pushed 2026-07-20T08:14:16Z
pinglanlab/PBox
凭阑红蓝工具箱PBox是由凭阑实验室安全团队开发的一款面向Windows系统的图形化(GUI)安全渗透集成工具箱。它旨在解决安全研究人员和渗透测试工程师在日常工作中需要单独下载、配置多种工具及其复杂运行环境的痛点。 | language: Python | stars: 7 | forks: 0 | updated 2026-07-22T09:47:09Z | pushed 2026-07-18T08:25:26Z
Knaithe/Shroud
多级代理工具,支持树状拓扑、五层加密、SOCKS5/端口转发/Tor/SSH隧道,专为渗透测试设计 | language: Go | stars: 1 | forks: 0 | updated 2026-07-07T12:44:16Z | pushed 2026-07-07T12:43:18Z
gehewu/Cortex
一个多角色渗透测试Agent | stars: 0 | forks: 0 | updated 2026-07-07T16:56:17Z | pushed 2026-07-07T16:56:09Z