momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 9238 条情报 漏洞监控 5506 / 网安开源项目 3732
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Statmatic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaS
CVE-2026-32612;e9db9966f508b6da7060a7db060a7dee;Statmatic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users wit...
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions tha
CVE-2026-32597;f0a7b5375cabed962c0efb40e72a0877;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS to...
soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values using their raw U256 representation without first
CVE-2026-32322;f5e565c5cb2ebe551df579e78721cc5a;soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values us...
Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR encryption or integrity protection algori
CVE-2026-32320;d3b4e01ae000cfc2f2a5ddcb77c866e6;Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-len...
Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. An attacker able to send crafted NAS me
CVE-2026-32319;df92465fc1ef4287fc130425761b8044;Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under ...
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is ena
CVE-2026-32598;9572e555b28f55b9847a1b7555fb035a;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plainte...
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This con
CVE-2026-32308;5e0efb744b58b068a8a1e110e93d316c;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" an...
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parame
CVE-2026-32306;144da95fd33b986b0b4055b022873475;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColum...
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without
CVE-2026-32304;5e33736646f9d2eca85fb0abc8a83855;Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both paramete...
OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-proxy and the request arrived with proxy headers.
CVE-2026-32302;bb4f945ffe8cb086dfedeba4ee842dc6;OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-p...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
KaiiiMonroe/Edraw-Max-Latest-Patch
🛠️ Create clear and professional diagrams effortlessly with Edraw Max, the versatile software for visualizing ideas and enhancing collaboration. | topics: business-diagramming-windows, edraw-max-business-presentation, ed...
david3c2004/CLR-Unhook
🛡️ Bypass EDR/AV hooks in .NET CLR by restoring the original `nLoadImage` function for seamless assembly loading without security inspection. | topics: ai, analytics, awesome, clickhouse, common-lisp, concept-learning, d...
jorrip12/windows
🛡️ Streamline Windows endpoint security with Sentrilite EDR/XDR—real-time threat detection, observability, and AI-driven insights without heavy agents. | topics: button, csharp, debloat, docker, exploitation, exploiting-...
Sahand-Edrisi/sahand-edrisi
language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-16T01:09:25Z | pushed 2026-03-16T01:09:21Z
dre5525/EDRStartupHinder
🛑 Prevent Antivirus and EDR from starting by redirecting core DLLs during Windows startup with EDRStartupHinder for enhanced system control. | topics: amsi-bypass, av-evasion, defense-evasion, dinvoke, edr-evasion, free,...
emmanuel806/CCTV-EDR
topics: bilibili, cctv-detection, cctv-mo, censorship, censorship-circumvention, china-dictatorship, chinese-communist-party, covid-19-china, dictatorship, docker, falun-gong, gfw, github-config, great-firewall, human-ri...
Rakum713/ColdWer
🥶 Freeze EDR/AV processes with ColdWer, using WerFaultSecure.exe PPL bypass to extract LSASS memory on modern Windows systems. | topics: av-bypass, beacon-object-file, bof, cobalt-strike, credential-dumping, edr-bypass, ...
MrSpaghettiBK/rustinel
🔍 Detect threats with Rustinel, a high-performance Windows EDR agent that leverages ETW to collect telemetry and outputs alerts for easy SIEM integration. | topics: api, api-platform, detection-engineering, edr, endpoint...
haydnvn/EdricSongs
language: Python | stars: 0 | forks: 0 | updated 2026-03-16T01:30:10Z | pushed 2026-03-16T01:24:00Z
mohamedanas069/CS-EDR-Enumeration
🛡 Enumerate AV, EPP, EDR, and telemetry on Windows hosts using low-noise Cobalt Strike commands for tailored risk-based assessment. | topics: aggressor-script, beacon-object-file, bof, cobalt-strike, cobaltstrike-cna, ed...