momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 4718 条情报 漏洞监控 2945 / 网安开源项目 1545 / 威胁情报 228

漏洞监控

来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。

2945总量

网安开源项目

优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。

1545总量

威胁情报

来自 360、奇安信、斗象等官方站点的公开情报聚合。

228总量
blaxkmiradev/CVE-2026-21847-Hardcoded-AES-Encryption-Key-in-DPDC-Customer-Portal
language: Python
MAOGE555/shuidi
水滴工具箱,集合各种渗透工具。端口扫描器,漏扫,抓包,内存马,内网穿透,c2,免杀等等 | language: Python | stars: 107 | forks: 12 | updated 2026-04-24T12:37:48Z | pushed 2026-04-18T15:21:13Z
每周高级威胁情报解读(2026.04.10~04.16)
APT37 通过 Facebook 发起的有针对性入侵活动;APT35组织在“史诗之怒”冲突前对目标进行系统性网络侦察;Storm-2755 针对加拿大雇员进行“Payroll pirate”攻击;在 npm 上追踪 OtterCookie 信息窃取活动;研究人员成功获取Kimsuky三阶段完整攻击载荷源码
sivaadityacoder/CVE-2026-22038
SmallGreyHUI/wukedunxing
自动化渗透测试系统 | language: Python | stars: 0 | forks: 0 | updated 2026-04-21T18:44:38Z | pushed 2026-04-21T18:44:35Z
ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
dinosn/pack2theroot-lab
CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation | language: Shell
XuanMuSec/rpc_endpoint_map
由玄幕独立开发的135端口渗透的工具 | language: Python | stars: 4 | forks: 0 | updated 2026-04-26T04:29:25Z | pushed 2026-04-21T16:14:32Z
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
Introduction
Chromium: CVE-2026-6921 Race in GPU
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Fan-SecLab/Fan-SecLab.github.io
渗透测试 | language: CSS | stars: 3 | forks: 0 | updated 2026-04-25T13:23:38Z | pushed 2026-04-25T13:23:34Z
[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)
&#;x26;#;x5b;This is a Guest Diary by Alec Jaffe, an ISC intern as part of the SANS.edu Bachelor&#;x26;#;39;s Degree in Applied Cybersecurity (BACS) program &#;x26;#;x5b;1].
Chromium: CVE-2026-6919 Use after free in DevTools
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
kk12-30/Scan-X
Scan-X是一款AI赋能渗透测试的框架平台。 | language: HTML | stars: 187 | forks: 12 | updated 2026-04-21T13:47:34Z | pushed 2026-04-17T09:17:08Z
无条件接管Nginx!Nginx-UI漏洞链发现在野利用
立即查看详情 →
Hann1bl3L3ct3r/FUXAPWN
POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE | language: Python
Bu7terf1y/Bu-SubdomainX
Bu-SubdomainX - 高效的子域名枚举工具,支持多线程扫描、自定义字典和实时结果输出,为渗透测试提供全面的子域名发现能力。 | language: Python | stars: 3 | forks: 0 | updated 2026-04-23T04:11:44Z | pushed 2026-04-21T12:12:25Z
CVE-2026-33032 深度分析:nginx-ui MCP端点认证绕过导致 Nginx 服务器完全接管
nginx-ui 项目(一个开源的基于 Web 的 Nginx 管理界面)被披露存在严重安全漏洞 CVE-2026-33032(CVSS 9.8),该漏洞已被野外积极利用。Pluto Security 安全研究人员将此漏洞命名为 MCPwn。
0xBlackash/CVE-2026-21962
CVE-2026-21962 | language: Python
CN-big-cabbage/skill-promptfoo
LLM 提示词测试、模型评估与红队安全扫描框架,通过声明式 YAML 配置驱动自动化评估流水线,支持 CI/CD 集成,被 OpenAI 和 Anthropic 内部使用 | stars: 0 | forks: 0 | updated 2026-04-21T09:05:10Z | pushed 2026-04-21T09:05:05Z
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
<p>Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for ar...
Astaruf/CVE-2026-41653
CVE-2026-41653 - BentoPDF <= 2.8.1 - Stored XSS → File Exfiltration
12211725-star/hospital-vuln-scanner-mcp-v1.1.0
医院漏洞扫描系统 MCP 插件 - 14个工具、51个Nuclei模板、8327条知识库 | language: Python | stars: 1 | forks: 0 | updated 2026-04-21T08:32:41Z | pushed 2026-04-21T08:32:38Z
ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)
baph00met/CVE-2026-41651
CVE-2026-41651 — PackageKit TOCTOU LPE | language: Python
huxiaoqiao/workspace-ips-maker
stars: 0 | forks: 0 | updated 2026-04-21T04:58:40Z | pushed 2026-04-21T04:58:36Z
每日安全动态推送(26/4/15)
Codex 利用 World-Writable Novatek 驱动实现三星智能电视 Root;Strix AI 发现 etcd 严重认证绕过漏洞;特洛伊化的 CPU-Z 与 HWMonitor 通过 DLL 侧加载分发 STX RAT
tausifzaman/CVE-2026-3844
PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE. | topics: automation, cve, cve-2026-3844, exploit, hacking-script, hacking-tool, poc | la...
ZQ-Rookie-Hacker/myExploitServer
用于SRC漏洞挖掘与渗透测试中的csrf、xss、cors等漏洞的验证与利用 | language: HTML | stars: 0 | forks: 0 | updated 2026-04-21T04:52:51Z | pushed 2026-04-21T04:52:48Z
Apache Tomcat 远程代码执行漏洞,附漏洞自查方案
立即查看详情 →