momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9287 条情报 漏洞监控 5516 / 网安开源项目 3771
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack
CVE-2026-4191;2dbb3ea2c8b8b5d750511bb7342374ac;A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This mani...
A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be ex
CVE-2026-4190;ea0351329f8a5f5de9362d3957dbc515;A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort...
jwde/automerge-test
Testing auto-merge CVE-2026-1999 variant
lagathos/CVE-2026-25596
lagathos/CVE-2026-25595
lagathos/CVE-2026-25594
JSurquin/php-securite-lab
Lab pédagogique PHP – 27 failles intentionnelles à identifier et corriger (SQL injection, XSS, CSRF, session fixation, upload, LFI, RCE...) | language: PHP
skr3zh3t/Simple-RCE-Wildcard-Injection
language: Java
lagathos/CVE-2026-25548
4nuxd/omrs-rce
Automated exploit for CVE - Online Marriage Registration System 1.0 Unauthenticated file upload → RCE → Auto reverse shell (Windows & Linux targets) | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
NexifyMe/SecureWP360
NexifyMy Security is a modern, lightweight, and powerful security plugin for WordPress. It provides a comprehensive defense suite including a Web Application Firewall (WAF), heuristic malware scanner, and intelligent bru...
corazawaf/coraza-proxy-wasm
proxy-wasm filter based on Coraza WAF | topics: coraza-waf, coreruleset, hacktoberfest, modsecurity, proxy-wasm, waf, wasm | language: Go | stars: 185 | forks: 41 | updated 2026-03-16T18:33:48Z | pushed 2026-03-16T18:33:...
corazawaf/coraza-spoa
A wrapper for integrating the OWASP Coraza WAF with HAProxy's SPOE filters. | topics: coraza, haproxy, haproxy-spoa, waf, web-application-firewall | language: Go | stars: 155 | forks: 36 | updated 2026-03-16T18:34:24Z | ...
chrryAI/waffles
E2E | language: TypeScript | stars: 1 | forks: 0 | updated 2026-03-16T18:35:24Z | pushed 2026-03-16T18:34:51Z | homepage: https://chrry.dev
JP-Romero/Kathy-s-Waffle-House
Desarrollar la pagina web que muestre el establecimiento con toda su oferta gastronómica, que los clientes puedan realizar ordenes directamente desde la pagina enlazados por WhatsApp, utilizando un gestor de base de dato...
Ziti-max/F14
🚀 Exploit NoSQL injection vulnerabilities effortlessly with F-14 Tomcat, featuring advanced data extraction and WAF evasion techniques for MongoDB. | topics: boardgames | language: Python | stars: 0 | forks: 0 | updated ...
sobuj0007/Nextjs_RCE_Exploit_Tool
🔍 Exploit CVE-2025-55182 in Next.js with this versatile tool for security research, featuring advanced payloads and WAF bypass techniques. | language: Go | stars: 0 | forks: 0 | updated 2026-03-16T18:49:49Z | pushed 2026...
anxb26/angie-modsecurity-docker
🛡️ Protect your web deployments with a production-ready Angie server, featuring ModSecurity WAF, Fail2Ban, and enhanced security through Docker Compose. | topics: angie, angie-docker-image, docker, docker-compose, docker...
kilouio91/turbo-waffle
language: JavaScript | stars: 0 | forks: 0 | updated 2026-03-16T18:54:07Z | pushed 2026-03-16T18:54:03Z
JLH-Xerus/WAF_Work
language: TSQL | stars: 0 | forks: 0 | updated 2026-03-16T18:55:05Z | pushed 2026-03-16T18:55:01Z