momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9296 条情报 漏洞监控 5519 / 网安开源项目 3777
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
watchtowrlabs/watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260
language: Python
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malici
CVE-2026-32694;97d5df37382ca329fc2a0c7fc6fe269f;In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the ...
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execut
CVE-2026-3278;62225a4b406567ff3ddbff7af9016435;Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The ...
Deserialization of Untrusted Data vulnerability in Shinetheme Traveler allows Object Injection.This issue affects Traveler: from n/a before 3.2.8.1.
CVE-2026-25449;b29196b06867d51dbabb233a4988285f
rce/mux
language: Rust
MoriartyPuth-Tools/bubble-scanner
A lightweight, event-driven API reconnaissance and vulnerability scavenger built in Bash. Engineered for proactive threat hunting, it automates endpoint discovery, secret scavenging, and RCE/SQLi probing. | topics: apise...
A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and crea
CVE-2026-32691;97631f123fa2c4efa2b0dc37ad900311;A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secr...
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With suffic
CVE-2026-32692;64c949ef447562c83a1f8501d86bad5b;An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unaut...
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. Wh
CVE-2026-32693;d9b3d1e0ef96fdb3a027d0aa23a57ea0;In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and c...
Areeba-Zehra-Jafri/CVE-2021-41773---Apache-Path-Traversal---RCE
language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
jfrancci/iris-ransomwarelive-module
IrisRansomwareLive enriches DFIR-IRIS cases with real-time ransomware threat intelligence sourced from Ransomware.live. | language: Python | stars: 0 | forks: 0 | updated 2026-03-20T20:26:18Z | pushed 2026-03-20T20:26:14...
mthcht/ForensicArtifacts2DFIR-orc-config
topics: artifact, converter, dfir, forensics | language: Python | stars: 0 | forks: 0 | updated 2026-03-21T07:11:11Z | pushed 2026-03-21T07:11:08Z
shakibul742/DFIR-Journey
My journey learning Digital Forensics & Incident Response (DFIR) — daily notes, tools, labs, and investigations. | stars: 0 | forks: 0 | updated 2026-03-21T17:33:44Z | pushed 2026-03-21T17:33:41Z
notanonymouse/Digital-Forensics-CTI-Library
A collection of my research, checklists and learning resources for DFIR and Threat Intelligence. | stars: 0 | forks: 0 | updated 2026-03-16T07:35:19Z | pushed 2026-03-16T07:35:15Z
valITino/dfireballz
AI-native digital forensics & cybercrime investigation platform. 7 MCP servers (Volatility3, Ghidra, Wireshark, OSINT, threat-intel & more) orchestrated by Claude, ChatGPT, or Ollama — fully containerized, chain-of-custo...
glantheman/GhostLens
A Windows forensic triage tool that spins up a local web dashboard on a potentially compromised host. Designed for IR first-responders who need a fast "first aid" assessment, not a replacement for enterprise DFIR suites,...
AnttiKurittu/incident-report-template
Generic DFIR report template | language: HTML | stars: 29 | forks: 8 | updated 2026-03-20T10:35:23Z | pushed 2026-03-20T10:35:21Z
redzeptech/VoxTrace-DFIR
The All-in-One Forensic Timeline Reconstructor. Seamlessly integrate Audio Forensics with Windows Artifacts. VoxTrace-DFIR automates the collection and correlation of logs, file system activity, and speech evidence into ...
LongRangeBehaviorModificationSpecialist/SQL_Queries
Some useful SQL queries for DFIR | stars: 2 | forks: 0 | updated 2026-03-21T16:04:01Z | pushed 2026-03-21T16:03:58Z
MartMbithi/2-22-DFIR-Framework
Digital Forensic and Incident Response AI | language: Python | stars: 2 | forks: 0 | updated 2026-03-17T09:16:39Z | pushed 2026-03-17T09:16:35Z