momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9343 条情报 漏洞监控 5549 / 网安开源项目 3794
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
ry-allan/tanstack-compromise-checker
Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks (Claude Code, VS Code, systemd, LaunchAgent), GitHub workflows, git history, ...
HORKimhab/CVE-2026-20182
CVE-2026-20182 | language: Python
aexdyhaxor/CVE-2026-31431-copy-fail
CVE-2026-31431 merupakan celah keamanan yang terjadi akibat kegagalan dalam proses penyalinan data (copy operation failure). Kerentanan ini muncul ketika sistem tidak melakukan validasi atau penanganan error dengan benar...
unnaim/adbHijacker
A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled | language: Python
diamorphine666/CVE-2026-0926-exploit
CVE-2026-0926 exploit. The Prodigy Commerce plugin for WordPress Local File Inclusion | language: Python
diamorphine666/CVE-2026-0770
Langflow remote code execution exploit | language: Python
Pumila03/CVE-2026-6009
language: Python
zycoder0day/CVE-2026-5118
CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection
webdev75950-ux/nginx-rce-cve-2026-42945
xxconi/CVE-2026-6960
CVE-2026-6960: BookingPress Pro <= 5.6 – Unauthenticated Arbitrary File Upload | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
wangziling-rgb/web-pentestagents
一个让Ai模型进行完全自动化web渗透测试的项目。你只需要提供域名或网址。 | language: Python | stars: 2 | forks: 1 | updated 2026-03-21T05:20:07Z | pushed 2026-03-21T05:20:03Z
doki-byte/EasyTools
EasyTools - 一个简单方便使用的渗透测试工具箱,集成了工具仓库、网址导航、简练助手、CTF合集、代理池、cli脚本定时执行等诸多功能。 | topics: easytools | language: Go | stars: 238 | forks: 18 | updated 2026-03-18T10:57:11Z | pushed 2026-03-17T14:56:30Z
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript | topics: bug-bounty, ctf, cybersecurity, hacking-tools, infosec, owasp, payload, penetration-testing, pentest, react, red-team, se...
FX42S/Sqlmap-FluX
SQLMap-FluX 是针对sql注入的改造版本。本项目核心在于通过重构工具的静态特征、逻辑载荷以及交互行为,使其能够模拟拟人化的访问模式,从而在渗透测试中,有效检测并绕过现代Web应用防火墙的特征识别与频率检测。 | language: Python | stars: 24 | forks: 0 | updated 2026-03-17T15:39:26Z | pushed 2026-03-11T09:49:58Z
De1ty-XD/web
web渗透学习记录 | stars: 0 | forks: 0 | updated 2026-03-19T14:38:51Z | pushed 2026-03-19T14:38:41Z
SeaC-25/Kali-Security-MCP
Kali MCP 是一套 LLM 自主多智能体渗透系统,依据「向量化知识库 + 联网搜索 + 自身能力」逐步动态规划下一步 | language: Python | stars: 78 | forks: 16 | updated 2026-08-17T17:53:23Z | pushed 2026-08-17T07:54:35Z
RICARDOCRC735/NavicatPwn
针对Navicat的后渗透利用框架 | topics: hacking, navicat, navicatpwn, pwn | language: Python | stars: 2 | forks: 1 | updated 2026-03-22T13:50:09Z | pushed 2026-03-22T13:50:06Z
F3ank/ApiScanPlus
Burpsuite插件用于接口路径渗透测试 | stars: 17 | forks: 1 | updated 2026-03-19T01:28:08Z | pushed 2026-03-13T06:01:17Z
steveopen1/skill-play
面向 AI Agent 的渗透测试技能库,自动化攻防与漏洞探测能力集 | stars: 5 | forks: 0 | updated 2026-03-20T10:06:59Z | pushed 2026-03-17T16:02:31Z
vision-dev1/VisionX-Linux
Lightweight Debian OS packed with full offensive security tools for power users. | stars: 3 | forks: 0 | updated 2026-03-17T15:26:51Z | pushed 2026-03-17T15:26:43Z