momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 7159 条情报 漏洞监控 4634 / 网安开源项目 2525
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
J4ck3LSyN-Gen2/CVE-2026-58457
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educatio...
Ch4120N/CVE-2026-55579
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies. | topics: cve, cve-2026, cve-2026-55579, cwe-798, cwe-9...
CerberusMrXi/WP-Contest-Gallery-28.1.4-Exploit
Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and r...
justsoman/CVE-2026-43499-jinghu
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
hakaioffsec/CVE-2026-40083
SQL Injection at Cacti | language: Python
bibotai/secveri-cve-2026-50011-negative
language: Java
bibotai/secveri-cve-2026-50011-positive
language: Java
MoxitPanchal/EverShop-Lab-CVE-2026-25993
language: JavaScript
nabhan-mohy/cve-2026-27483-lab
A containerized enterprise-style lab for researching and defending against CVE-2026-27483. | language: Shell
jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
Proof-of-concept for CVE-2026-43284 — 4-byte XFRM/ESP page-cache write primitive to patch a setuid binary (x86_64, user namespaces). Includes kernel preflight + SUID scan. | language: C
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
icecliffs/nextanti
NextAnti is a browser extension focused on anti-honeypot and anti anti-honeypot techniques, NextAnti 是一款专门用于浏览器反蜜罐反反蜜罐(Anti-Honeypot)的插件,自动阻断蜜罐请求,被蜜罐溯源,皆在于快速被蓝队识破并反制红队小伎俩 | topics: anti, antihonypot, attack-defense, blue...
PuppetWen/RedScope-AI
RedScope AI 是一个面向安全团队、渗透测试、资产侦察、威胁追踪和红队编排的 AI CLI。它基于 Bun、TypeScript、React/Ink 和 MCP 工具生态构建,提供交互式终端助手、非交互式管道模式、多模型 Provider、插件系统、远程控制服务和一套受控的安全工作流脚本 | language: TypeScript | stars: 97 | forks: 19 | updated 2026-07-30T11:...
shangdi-w/-skills
Hermes Agent 红队技能库 | 全平台反编译(18类) + 免杀对抗(18章入门到专家) | 仅供授权安全测试使用 | topics: av-evasion, decompile, hermes-agent, pentesting, redteam, reverse-engineering, security | stars: 6 | forks: 1 | updated 2026-07-08T02:21:43Z | push...
guaidao2/xuanmu-smart-malware-detect
玄幕安全团队自设计架构的智能杀毒软件引擎,由于是在Linux中训练,尚未开发Windows版本的界面,后续添加。(该项目不仅可以查杀木马,还可以让红队来测试自己的免杀能力) | language: Python | stars: 0 | forks: 0 | updated 2026-07-04T05:55:45Z | pushed 2026-07-04T05:52:58Z
Aurelius-zenon/redteam-rs-llm
redteam-rs 是一个面向大语言模型内容安全评测的红队测试框架,提供 CLI 与桌面端两种使用方式。它采用三层表征级越狱架构:L1 探测、L2 牵引、L3 突破,用于系统性地评估模型在安全对齐、越狱防护和提示注入场景下的表现。 | language: Rust | stars: 1 | forks: 0 | updated 2026-07-04T09:00:03Z | pushed 2026-07-04T08:59:20Z
Yn8rt/DDDD-DL
重构DDDD,与DLDL联动快速实现POC与指纹的结合,提高红队资产发现与打点效率 | stars: 56 | forks: 3 | updated 2026-08-06T11:52:01Z | pushed 2026-07-24T06:59:58Z
nico-zhuang/ask-five-pro
Ask Five Pro — 开箱即用的专家议会系统,内置 34 位跨领域专家,支持共识/对抗/红队/陪审团/预审/淬火六种议会模式。v2.0.6 | language: Python | stars: 3 | forks: 0 | updated 2026-08-01T05:30:03Z | pushed 2026-08-01T05:29:58Z
icecliffs/nextwq
QQ小程序反编译逆向/微信小程序反编译逆向/红队攻击面分析/快速漏洞/检查/筛查 | stars: 62 | forks: 5 | updated 2026-07-27T06:21:38Z | pushed 2026-06-13T04:14:17Z
chAng-L19/codex-redteam-mode
针对于红队攻击思维做出的red team模式(破限项目,封号概不负责)##可自行适配其他Agent。项目问题请提issue | topics: ai, ai-hacking, hacking-tool, penetration-testing, red-team, redteam, redteam-tools | language: Python | stars: 925 | forks: 126 | updated 2026-08-0...
zzqsec/ai-redteam-notes
AI 驱动的红队免杀知识库 — AI-generated red team evasion notes | stars: 55 | forks: 10 | updated 2026-08-07T07:51:01Z | pushed 2026-06-23T13:45:54Z