momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9292 条情报 漏洞监控 5517 / 网安开源项目 3775
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43.
CVE-2025-13406;04084bf5c1f9af9816e3a9eb595d7115
A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by paramet
CVE-2026-4324;2ac6fcdc7ec581ae0ca753990f1b05d3;A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject ...
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This is
CVE-2026-3888;05e9e6128913244256f83fe3b90c27e5;Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to...
ThanniKudam/codex-notify-rce-poc
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. Wh
CVE-2025-62320;5d44d34d32e5e0efb070739e7a743500;HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker...
p0dalirius/CVE-2020-14144-GiTea-git-hooks-rce
A script to exploit CVE-2020-14144 - GiTea authenticated Remote Code Execution using git hooks | topics: cve-2020-14144, git, gitea, hook, rce | language: Python | homepage: https://podalirius.net/en/articles/exploiting-...
HCL Sametime is vulnerable to broken server-side validation. While the application performs...
CVE-2025-31966;7bfc69069a1ecef6d3725c15183c5874
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a...
CVE-2026-4271;9bcc80b93388e4a8e86b2fef7f90d392
Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version meta
CVE-2026-26929;cec02fc8ef4435c5a64303e9989d10d2;Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (w...
Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission
CVE-2026-28563;4be0d11524f2fd77526f7212c1fb6c5a;Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenti...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
sinocikid/sinocikid.github.io
AndyCyberLife - Cybersecurity blog sharing insights on threat analysis, security tools, and defense strategies | language: CSS | stars: 0 | forks: 0 | updated 2026-03-22T15:00:15Z | pushed 2026-03-22T15:00:10Z | homepage...
shriVBA/cyber-security
This repository contains Cyber Security learning materials, notes, and practical examples designed for beginners and students preparing for IT and Cyber Security roles. It includes concepts related to networking, Linux, ...
BarakMozesPro/secureflow-mcp
MCP tools server with multi-transport client/server and security tool registry | topics: ai-tools, mcp, model-context-protocol, protocol, sdk, server-framework, typescript | language: TypeScript | stars: 0 | forks: 0 | u...
opena2a-org/opena2a
Open-source security tools for AI agents. Find vulnerabilities, fix root causes, prove compliance. | topics: agent-security, ai-agents, ai-security, claude-code, compliance, copilot, credential-protection, cursor, llm-se...
elementsinteractive/twyn
Security tool against dependency typosquatting attacks | topics: pipeline, python, security, security-tools, typosquatting | language: Python | stars: 55 | forks: 5 | updated 2026-03-17T13:31:54Z | pushed 2026-03-17T13:3...
D3fD3c0y/Online-security-tools-framework
Visual graph to identified Online security tools related to Threat Intelligence | language: JavaScript | stars: 0 | forks: 0 | updated 2026-03-17T16:11:43Z | pushed 2026-03-17T16:11:39Z
JK-xpinn/jkspinnn-security-research
Cybersecurity research portfolio including web security testing, malware analysis, threat intelligence investigations, and security tools. | stars: 0 | forks: 0 | updated 2026-03-18T00:17:07Z | pushed 2026-03-18T00:17:04...
simonech/Umbraco.Community.SecurityToolkit
A set of security improvements for Umbraco | stars: 0 | forks: 0 | updated 2026-03-16T16:34:12Z | pushed 2026-03-16T16:34:09Z
ByteScan-Labs/HZP
A Java library for parsing ZIP archives with structural anomalies or evasion techniques commonly used to bypass security tools. | language: Java | stars: 0 | forks: 1 | updated 2026-03-16T16:39:31Z | pushed 2026-03-16T16...
Edgar-GIT/GO-MULTITOOL
An advanced offensive security tool for experts. Developed in GOLANG, it uses complex algorithms to achieve the most amount of efficiency and provide with the best results. | language: Go | stars: 1 | forks: 0 | updated ...