momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9292 条情报 漏洞监控 5517 / 网安开源项目 3775
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same dom
CVE-2026-28779;fdca579da20883c806544a3c17615fae;Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This all...
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workf
CVE-2026-30911;189b156ab1c19903afc5dd296f757e6c;Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task...
In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at" variant of getxattr() and listxattr() are missing from the audit read class. Calling getxattrat() or
CVE-2026-23241;e48ddd7e37f2d90749da86baf5fd24d0;In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at" variant of getxattr() and listxattr() are missing fro...
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP h
CVE-2026-3632;6b72ed0c1acdee01ef0e372cafea3e89;A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowin...
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Car
CVE-2026-3633;5d4db0b2c0e16606853d560c2bb5a28c;A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional reque...
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_se
CVE-2026-3634;32957ce382cbb6a8357c4046019c3bbf;A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper inp...
monarchfish/cve-2025-55182-poc
Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization. | language: TypeScript
Nothingness1312/RCE-Lab-Platform
RCE Lab Platfrom - Latihan Remote Code Execution (RCE) berbasis CTF, dengan vulnerability nyata, multi-level challange, dan setup cepat via docker | language: CSS
Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
Pre-auth SSH DoS via unbounded zlib inflate
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
huntridge-labs/argus
Argus brings “a hundred eyes” to your project, combining leading open source security tools into a scalable, automated, continuous security pipeline. | topics: fedramp, hardening, security-tools | language: Python | star...
Harvester57/sudoers-audit
sudoers-audit is a security tool designed to audit sudoers files for potential security risks and misconfigurations | language: Python | stars: 0 | forks: 1 | updated 2026-03-16T17:54:44Z | pushed 2026-03-16T17:54:46Z
JKG-cpu/CyberSecurity-Tools
language: JavaScript | stars: 0 | forks: 0 | updated 2026-03-20T15:21:41Z | pushed 2026-03-20T15:21:36Z
florentvinai/bad-ips-on-my-vps
A curated list of malicious IPs blocked by security tools on my server. These addresses attempted attacks or unauthorized access. The database updates hourly if new threats are found, aiming to build a real-time threat f...
vagdevi08/DevSecOps-Project
DevSecOps pipeline for Python based project using Jenkins, Ansible, AWS, and open-source security tools and checks. | language: Python | stars: 0 | forks: 0 | updated 2026-03-16T19:00:45Z | pushed 2026-03-16T19:00:41Z
slamdad/The-Forge
Cool Page for My Developing and Security Tools Records | language: Python | stars: 0 | forks: 0 | updated 2026-03-22T15:51:28Z | pushed 2026-03-22T15:51:24Z
shaylaing/password-security-toolkit
Created for my CS50x final project. Includes a simple password strength checker that provides recommendations to improve password strength, and a password attack simulator that provides the user with the estimated time i...
Lyrothanak20/Impacket_Reference
Provide complete documentation and examples for all 68 Impacket scripts to simplify network protocol and security tool usage. | topics: bash, dcerpc, grep, hash, impacket-gui, impacket-web, javascript, kerberos, pentest-...
RELIAX1212221/RedTeam-MCP
Automate red teaming by using AI to plan attacks, run security tools, move laterally, and escalate privileges in network environments. | topics: active-directory, ai-agent, ai-security, bloodhound, cybersecurity, ethical...
meh2133/skills
Provide AI agents with modular skills to use open-source security tools for labs, browser simulation, and code sandboxing. | topics: agent-skills, ai-agents, archive, astro, autonomous-coding, claude-code, clawdbot, claw...