momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 7146 条情报 漏洞监控 4628 / 网安开源项目 2518
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Jvr2022/CVE-2026-46420
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution. | topics: command-injection, cve-2026-46420, cwe-78, github-actions, poc, security-research, setup-php
ChiefYoru/CVE-2026-63030_PoC
CVE-2026-63030 - WordPress Core Pre-Auth RCE Mass Exploit | language: Python
yoerivegt/wp2shell-poc
wp2shell (CVE-2026-60137 / CVE-2026-63030) | language: Python
0xWhoknows/wp2shell
Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes, cracks credentials, deploys webshell. Supports single target and bulk ...
Eangly/CVE-2026-21978
My CVE in Oracle FLEXCUBE Universal Banking
mrx-arafat/CVE-2026-63030-POC
language: Python
h4cd0c/wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7....
Arturo0x90/CVE-2026-51385
Advisory for CVE-2026-51385. Needed to publish it as GRAPHIFY hasnt recognized the advisory neither publish it, and MITRE assigned CVE-2026-51385, this is the advisory for it.
Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall
CVE-2026-43499 reproduce in Xiaomi 17T. (kernelsu incomplete)
shinthink/CVE-2026-14894
Super Forms Unauthenticated File Upload RCE | CVSS 9.8 | topics: 0day, cve, exploit, file-upload, pentest, security, vulnerability, wordpress | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
nexorin9/qc-rule-red-team
基于 Z3 约束求解器的医疗质控规则红队工具,自动生成边界病例测试规则覆盖度,输出漏洞报告与可视化图表,支持多格式规则导入。 | language: Python | stars: 0 | forks: 0 | updated 2026-05-23T15:42:29Z | pushed 2026-05-23T15:42:13Z
0x7556/hackvideo
Hack视频教程:红队渗透测试、金刚狼WolfShell、工具使用教程 | stars: 0 | forks: 0 | updated 2026-05-24T09:00:16Z | pushed 2026-05-24T09:00:12Z
dreamaeiou/BlackRelay
BlackRelay 是一个面向红队场景的 AI API 中转与审计工具。它位于 AI 客户端与上游模型 API 之间,负责转发请求、记录 Prompt 和工具行为、按规则扫描敏感信息,并在 Claude 风格的流式响应中注入额外工具调用。 | language: Go | stars: 1 | forks: 0 | updated 2026-05-30T11:18:25Z | pushed 2026-05-30T11:17:29Z
ctfd3219/StarS
StarS 一站式企业信息测绘与供应链风险探测工具,深度优化红队攻防作业链路,自动化替代人工重复工作,极速排查各类安全漏洞。 | topics: config, github-config | language: Go | stars: 1 | forks: 0 | updated 2026-05-31T05:45:26Z | pushed 2026-05-26T09:16:20Z | homepage: https://github....
fenghot/XSS_agents
基于LangGraph + DeepSeek的AI驱动XSS渗透测试系统。模拟红队专家的完整思维链——通过浏览器内改包绕过前端防御,结合GAN驱动持续进化,实现低误报、高效率的XSS漏洞深度挖掘。 | topics: ai-security, deepseek, langgraph, llm-agents, penetration-testing, red-teaming, xss-detection | language: Pytho...
prof-faustus/mental-poker-zh
Mental Poker(BSV 心智扑克)简体中文翻译版:无荷官扑克规范/架构/红队文档与手牌评估参考实现,全部译为简体中文(代码不变;二进制论文未纳入)。Simplified-Chinese localization of the Mental Poker (BSV dealerless poker) spec, architecture, red-team docs and hand-eval oracle. | language...
nexorin9/hospital-cloud-adversarial-tester
医院云端对抗性测试平台,用红队思维模拟云账号误封/服务中断等极端场景,验证HIS紧急响应流程漏洞并生成整改清单;基于FastAPI+Typer CLI,提供场景卡引擎、红队剧本、漏洞分析、HMAC审计链等六大模块,支持Docker一键部署 | language: Python | stars: 0 | forks: 0 | updated 2026-06-04T18:13:16Z | pushed 2026-06-04T18:12:20...
yuxing28/-PRISM
这是一个名为 "智镜 PRISM" 的 AI 决策辅助系统,基于 Next.js 16 + React 19 构建。用户输入决策问题后,系统通过 DeepSeek API 进行结构化分析(含多维评分、红队对抗、信息收集等模式),并将分析结果以流式方式呈现,同时在侧边栏显示雷达图和仪表盘。 | language: TypeScript | stars: 1 | forks: 1 | updated 2026-06-05T05:53:09Z...
Bouquets-ai/StrikeAgent-RedInit
面向红队侧的以严重漏洞直到RCE为主 | stars: 0 | forks: 0 | updated 2026-06-06T17:44:09Z | pushed 2026-06-06T17:44:06Z
xieguanting/
AI红队攻防研究实验室,收录OpenClaw技能、LLM边界测试、参数篡改与越权检测等实战工具,仅用于安全研究与防御优化。 | language: Python | stars: 2 | forks: 0 | updated 2026-06-09T09:15:24Z | pushed 2026-06-08T14:19:02Z