momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9343 条情报 漏洞监控 5549 / 网安开源项目 3794
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
sermikr0/CVE-2026-38426
CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3) | topics: buffer-overflow, cve, esp32, iot, security, strcpy, tasmota, vulnerability
sermikr0/CVE-2026-38422
CVE-2026-38422 — Remote Code Execution via Combined Buffer Overflows in Tasmota fetch_jpg() (Tasmota <= 15.3.0.3) | topics: buffer-overflow, cve, esp32, iot, rce, security, tasmota, vulnerability
learner202649/CVE-2026-47101-PoC
The code for personally reproducing the corresponding vulnerability | language: Shell
kx00007/CVE-2026-35196
Second CVE still Remote Code Execution
tstephens1080/palo-alto-cve-2026-0265-checker
Python script to sweep a fleet of Palo Alto firewalls and Panoramas via SSH, check PAN-OS version against CVE-2026-0265 (Authentication Bypass via Cloud Authentication Service), detect whether CAS is actually configured,...
xShadow-Here/CVE-2026-4885
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE | language: Python
mein-0/cve-2026-29923
language: C
CatchCatOoO/CVE-2026-39636-vulnerability-exp
暂无 | language: Python
retmakarunia/CVE-2026-48172
cPanel user run arbitrary scripts as root
AtlasVector/Dirty-Frag-CVE-2026-43284
Lab detection exercise for DirtyFrag (CVE-2026-43284) - Linux kernel privilege escalation via xfrm-ESP page cache corruption. Full write-up covering exploit execution, detection gaps, and corrected EQL rules using Elasti...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
figoyu/pentest-tutor-system
AI Agent驱动的Web渗透测试课程陪练系统 | language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-17T00:36:21Z | pushed 2026-03-17T00:36:16Z
Muscial/Mus_Agent
黑盒渗透Agent | language: Python | stars: 4 | forks: 0 | updated 2026-03-17T00:40:07Z | pushed 2026-03-13T02:41:51Z
qazwsx5293870/S-XIASQL
S-XIASQL 是一款专业的 Burp Suite SQL注入检测插件,能够自动化检测Web应用中的SQL注入漏洞。通过智能分析HTTP请求响应,快速识别潜在的SQL注入点,大幅提升渗透测试效率。 | stars: 64 | forks: 2 | updated 2026-03-19T12:07:40Z | pushed 2026-03-16T17:53:32Z
Rubby2001/Rshell---A-Cross-Platform-C2
Rshell是一款开源的golang编写的支持多平台的C2框架,旨在帮助安服人员渗透测试、红蓝对抗。 | language: Go | stars: 525 | forks: 135 | updated 2026-07-07T09:30:19Z | pushed 2026-07-07T09:30:33Z
arch3rPro/PST-Bucket
Scoop-Buket for Penetration Suite Toolkit - Windows渗透测试工具仓库For Scoop | topics: pentest-tools, scoop-bucket, windows-penetration-testing | language: PowerShell | stars: 246 | forks: 44 | updated 2026-09-09T12:40:06Z | pus...
Mr-xn/Penetration_Testing_POC
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms | topics: authenti...
threehammers-group/SwordfishSuite
SwordfishSuite - Web安全测试利器 一款轻量、高速、插件化的现代Web安全测试工具,专为安全研究员和渗透测试者打造。 ✨ 核心特性: 智能代理:无缝拦截与修改HTTP/S请求,流畅度超越BurpSuite。 高度集成:集成云端虚拟手机,快速定位APP漏洞。 强大插件:支持自定义Python扩展插件,轻松定制专属功能。 直观界面:提供清晰直观的GUI操作体验。 致力于成为安全研究员手中最锋利的剑。让安全测试变得更简单、更...
zhanglimao/Abyss
基于AI多智能体的自主渗透测试框架 | language: JavaScript | stars: 20 | forks: 2 | updated 2026-07-23T04:38:18Z | pushed 2026-07-19T16:49:47Z
adysec/ARL
ARL 资产侦察灯塔系统(可运行,添加指纹,提高并发,升级工具及系统,无限制修改版) | ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。 | topics: arl, cyber-security, flask, fofa, python, scan, secu...
iammm0/secbot
⚠️ 本工具仅用于授权的安全测试。未经授权使用本工具进行网络攻击是违法的。一个智能化的自动化渗透测试机器人,具备AI驱动的安全测试能力。 | topics: langchain, langgraph, ollama, react-ink, sqlite-vec | language: Python | stars: 41 | forks: 7 | updated 2026-03-22T09:14:29Z | pushed 2026-03...