momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 4722 条情报 漏洞监控 2947 / 网安开源项目 1545 / 威胁情报 230

漏洞监控

来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。

2947总量

网安开源项目

优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。

1545总量

威胁情报

来自 360、奇安信、斗象等官方站点的公开情报聚合。

230总量
Microsoft Power Apps 远程代码执行漏洞
tybghii/tech-nnbk
网络安全工具箱 | stars: 0 | forks: 0 | updated 2026-04-20T01:57:37Z | pushed 2026-04-20T01:57:34Z
ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)
Microsoft Dynamics 365 (online) Spoofing Vulnerability
tybghii/tech-lqva
网络安全工具箱 | stars: 0 | forks: 0 | updated 2026-04-19T20:30:40Z | pushed 2026-04-19T20:30:39Z
Number Usage in Passwords: Take Two, (Thu, Apr 9th)
In a previous diary [1], we looked to see how numbers were used within passwords submitted to honeypots. One of the items of interest was how dates, and more specifically years, were represented within the data and how t...
Microsoft 365 Copilot 特权提升漏洞
tybghii/tech-upxu
网络安全工具箱 | stars: 0 | forks: 0 | updated 2026-04-19T20:28:19Z | pushed 2026-04-19T20:28:17Z
辟谣!Everything没被银狐投毒!
可以放心了
Microsoft Bing 远程代码执行漏洞
TakudzwaChoto/FedMD-XAI
FedMD-XAI: A Privacy-Preserving and Explainable Framework for Malware Detection using Federated Learning on PE Headers | language: Python | stars: 0 | forks: 0 | updated 2026-04-19T17:01:32Z | pushed 2026-04-19T17:01:27Z
TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)
This is the seventh update to the TeamPCP supply chain campaign threat intelligence report,&#;x26;#;xc2;&#;x26;#;xa0;"When the Security Scanner Became the Weapon"&#;x26;#;xc2;&#;x26;#;xa0;(v3.0, March 25, 2026).&#;x26;#;...
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
tybghii/tech-ivsa
网络安全工具箱 | stars: 0 | forks: 0 | updated 2026-04-19T14:29:58Z | pushed 2026-04-19T14:29:57Z
More Honeypot Fingerprinting Scans, (Wed, Apr 8th)
One question that often comes up when I talk about honeypots: Are attackers able to figure out if they are connected to a honeypot? The answer is pretty simple: Yes!
EQSTLab/CVE-2026-0603
language: HTML
bigmanBass666/SCAUZJ-AutoStudy
SCAUZ红队自动化刷课工具 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-04-19T12:34:21Z | pushed 2026-04-19T12:20:11Z
“猪猪侠”的阴影:疑似某虚拟手机服务商官网安装包被供应链攻击
奇安信威胁情报中心红雨滴团队私有情报生产流程发现国内一家提供云手机、虚拟手机的服务商官网安装包疑似于2026年2月-3月底期间被替换,目前已经恢复正常,该事件造成大量政企终端被控。
m0r4a/CVE-2026-6018-9-Local-Privilege-Escalation-Chain
language: C
Pacemak1rsl/-Django
基于Django框架的漏洞扫描系统 | stars: 0 | forks: 0 | updated 2026-04-21T15:28:07Z | pushed 2026-04-21T15:27:53Z
ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884, (Wed, Apr 8th)
d0x-awrqxavc/CVE-2026-23744
language: Python
DuringApple/Dommy
针对Impacket域渗透框架的快速启动脚本 | language: Python | stars: 0 | forks: 0 | updated 2026-04-18T16:29:41Z | pushed 2026-04-18T16:29:37Z
A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)
Webshells remain a popular method for attackers to maintain persistence on a compromised web server. Many "arbitrary file write" and "remote code execution" vulnerabilities are used to drop small files on systems for lat...
Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input
spmonkey/GHR
Golden-hooped Rod是一款对于web站点进行漏洞扫描的工具。 | language: Python | stars: 107 | forks: 9 | updated 2026-04-18T14:17:11Z | pushed 2026-04-18T14:17:07Z
Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
<p>Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution.</p><p> </p><ul><li>Mozilla Firefox is a web browser used to access the Internet.</l...
github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer
ffftuanxxx/malware-classification-CNN-optimized
Phase-based optimization of malware classification CNN on Malimg dataset: 89.06% -> 98.48% val accuracy. EfficientNetB0 transfer learning + Focal Loss + oversampling + TTA. Fork of cridin1/malware-classification-CNN. | l...
龙虾陷阱 | 伪装 OpenClaw 投递后门事件分析
精心搭建的仿冒站点、暗藏杀机的 JPG 图片、一段永不落地磁盘的恶意代码——攻击者正在利用开源 AI 工具的热度,编织一张精密的猎杀网络。