momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 10890 条情报 漏洞监控 6347 / 网安开源项目 4543
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
httpd mod_auth directory protection bypassed by a doubled slash in the request path
inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
uri_string does not bound the port component of a URI before integer conversion
httpc memory exhaustion via unbounded response header accumulation
Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Missing Authorization in Elasticsearch Leading to Information Disclosure
FIPS mode assertion failure via malicious CERT payload
rmhowe425/POC-CVE-2026-0769
Proof of concept exploit code for CVE-2026-0769 | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
zyjzyjlh3-alt/ai-pentest-agent
AI 自动渗透测试代理系统,基于 CrewAI 框架,集成多种安全扫描工具和漏洞检测能力 | language: Python | stars: 0 | forks: 0 | updated 2026-08-31T14:23:51Z | pushed 2026-08-31T14:11:59Z
hater-us/Artex-update
黑板架构的自动化渗透Agent | language: Go | stars: 1 | forks: 0 | updated 2026-08-31T14:52:00Z | pushed 2026-08-31T02:05:08Z
fakedon/Qtzuu-pentest-toolbox
TGSEC社区 @TGSEC · 擎天柱@Qtzuu 渗透测试工具包 —— 假设驱动的授权红队渗透测试技能框架:15个域 + 状态机攻击链 + 证据账本引擎 | stars: 2 | forks: 3 | updated 2026-09-04T10:32:08Z | pushed 2026-08-31T17:25:11Z
JiuZero/90sqli-skills
面向已授权渗透测试 / CTF / 靶场场景的 SQL 注入验证与取证 AI Skill,将测试固化为低噪声、证据化、可复核的六环节流程。 | stars: 0 | forks: 0 | updated 2026-09-02T01:19:15Z | pushed 2026-09-01T02:07:05Z
sunminemei/kerberos-pentest
内网渗透skill | stars: 2 | forks: 1 | updated 2026-09-01T03:07:49Z | pushed 2026-09-01T03:07:37Z
okdkebm/plutox-sec-forge
AI自动渗透 | language: Python | stars: 1 | forks: 0 | updated 2026-09-01T03:39:53Z | pushed 2026-08-31T15:22:30Z
litsasuk/Unity
一个快速启动渗透测试脚本、程序和工具的控制台 | language: Python | stars: 1 | forks: 0 | updated 2026-09-01T03:57:30Z | pushed 2026-09-01T04:00:01Z
AAAAAAAAAA6-FY/VULNCLAW
VULNCLAW 渗透测试平台|AGPL-3.0-or-later WITH Classpath-exception-2.0 开源;37 BaseEngines × AI v100 编排;DAG 流水线;分布式 master-worker;Burp Suite 桥 v1.0.8;MCP 原生接口;商业授权见 README | language: Python | stars: 0 | forks: 0 | updated 2026-09...
kwekre/security-skills
1404 安全与渗透测试 Agent Skills — 自包含、跨平台、按 35 类整理 (pentest / CTF / red-team / OSINT / web-security) | topics: agent-skills, bugbounty, ctf, offensive-security, osint, pentest, red-team, security, skill, web-security | languag...
kwekre/ai-pentest-guide
从 0 到能打:一份带 AI 辅助的渗透测试开源教程(基础 → AI 方法论 → 靶场实战 → 报告) | topics: ai, beginner, ctf, cybersecurity, learning, pentest, red-team, security, tutorial, web-security | stars: 0 | forks: 0 | updated 2026-09-01T07:04:03Z | pushed ...