momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9389 条情报 漏洞监控 5578 / 网安开源项目 3811
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
striga-ai/CVE-2026-23918
Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE. | language: Python
0xCyberstan/CVE-2026-53360-POC
PoC for CVE-2026-53360: guest-triggered heap out-of-bounds read/write in KVM SEV-SNP Page State Change (PSC) handling. | language: C
Mkps/CVE-2026-38751-OpenSTAManager-Arbitrary-File-Upload-PoC
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an authenticated attacker to upload a malicious module via the module update functio...
0xCyberstan/CVE-2026-31694-POC
Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a page-cache page by 24 bytes. PoC plus an unprivileged local-root exploit via /etc/passwd page-cache corruption. Ru...
yayip/CVE-2026-33017
PoC of Langflow CVE-2026-33017 | language: Shell
aquace/CVE-2026-41940-PoC
CVE-2026-41940 authentication bypass vulnerability proof-of-concept | topics: cpanel, cve, cve-2026-41940, cve-2026-41940-poc | language: Python
murrez/CVE-2026-6433
PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk multi-threaded scanning. Authorized testing & research only. | language: Py...
shaheryar773/mitigate-cve-2026-23869-react-server-component-loops
Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.
Nxploited/CVE-2026-12416-CVE-2026-12417
Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account T...
0xFuffM3/CVE-2026-31635-DirtyDecrypt
language: C
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
hartlez022/jdYNdOFAzh
【Java计算机毕业设计分享】基于SSM的漏洞扫描器管理系统,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-06-28T07:54:11Z | pushed 2026-06-28T07:54:07Z
huocai250/Webscanner
全功能 Web 漏洞扫描工具 | language: Python | stars: 25 | forks: 3 | updated 2026-09-10T02:19:02Z | pushed 2026-09-07T03:26:58Z
oopsoplm/Aakian-FaCai
基于前端vue框架的JavaFx图形化GUI漏洞扫描工具,支持一键扫描vue-manage-system系统前端泄露的未授权目录接口漏洞,并且对扫描的暴露目录进行逐一测试和验证,方便渗透人员快速确定未授权接口。还添加了出口IP地址信息本地DNS信息等的查询,方便清楚自身出口IP。 | stars: 0 | forks: 0 | updated 2026-06-28T10:37:44Z | pushed 2026-06-28T10:37:...
ijabyregra/mugSGWofZJ
【Python计算机毕业设计分享】基于Python的注入漏洞扫描工具研究及防护实现,MySQL Python开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-06-28T23:16:15Z | pushed 2026-06-28T23:16:11Z
Mental-6184/Sec-sonar
结合主动漏洞扫描与被动 RASP 运行时防护,构建完整的 Web 安全防御体系 | language: Java | stars: 0 | forks: 0 | updated 2026-06-30T10:46:15Z | pushed 2026-06-16T08:01:10Z
One-JiaSuo/Jiasuo-tools
枷锁工具箱是一套面向 macOS 的安全测试工具集合,把常用的安全能力按场景整理到 一个统一入口里,覆盖信息收集、漏洞扫描、漏洞利用、中间件测试、数据库利用、 WebShell 管理和后渗透辅助。工具箱既支持图形界面,也支持通过 geshell 进行命令 行调用,并且为一部分工具提供了 AI 可调用接口,便于自动化执行、批量检查和标准 化操作。项目还针对 macOS 做了启动修复、JDK 探测、Python 依赖和 venv 管理,支 ...
CllmsyK/YYBaby-Spring_Scan
一款针对Spring框架的漏洞扫描及漏洞利用图形化工具 | stars: 236 | forks: 11 | updated 2026-07-31T13:49:31Z | pushed 2026-06-13T06:52:36Z
systemime/fast_scan_tool
专注于在多租户虚拟子网的命名空间中,进行资产扫描和漏洞扫描的工具,如OpenStack Neutron,K8S的Pod中。基于Fscan+Nuclei | language: Go | stars: 0 | forks: 0 | updated 2026-07-27T11:57:10Z | pushed 2026-07-14T08:41:19Z
jahnfrens/sHSnIHbREZ
【Python计算机毕业设计分享】基于Python的web渗透漏洞扫描工具研究与应用,MySQL Python开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-07-03T16:04:12Z | pushed 2026-07-03T16:04:08Z
lizhianyuguangming/TomcatScanPro
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含 | topics: hacker, hackertools, penetration-testing-tools, scan, scanner-web, tomcat, tools | language: Python | stars: 2...