momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 7175 条情报 漏洞监控 4642 / 网安开源项目 2533
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Yakayna/SpringPeace
(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499 | language: Python
0xmrma/CVE-2026-34048
Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and execute commands on team servers.
4qu4r1um/tugtainer-1.30.2-RCE
A combination of CVE-2026-55494 and GHSA-c2h5-ppv9-7vrq to get root privilege RCE in tugtainer | language: Python
oscerd/CVE-2026-43867
Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE) | topics: apache-camel, cve, proof-of-concept, security, vulnerability | language: Jav...
Is4yev/CVE-2026-57830
Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830 | topics: cve, exploit, file-deletion, joomla, joomla-plugin, rce | language: Python
Is4yev/CVE-2026-57829
Unauthenticated Stored XSS in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 | topics: ato, cve, exploit, joomla, joomla-plugin, rce, xss | language: Python
Add optional JEP-290 ObjectInputFilter support to DefaultSerializer, with a conservative default on RememberMe deserialization
--- Following a thread on security@shiro.apache.org, where the PMC suggested opening this publicly for broader review. ## Background `DefaultSerializer#deserialize(byte[])` builds an `ObjectInputStream` and calls `rea...
Thiasap/oppo-pgem10-ghostlock
OPPO Find X6 Pro GhostLock (CVE-2026-43499) exploit adaptation | language: C
HORKimhab/CVE-2026-53805
CVE-2026-53805 - Draft | homepage: https://www.vulncheck.com/blog/nvidia-gen3c-unauth-pickle-rce
1beelze/CVE-2026-5118
language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
pqoeiekakzbc647483/blockchain-innovate-contract-suite
一站式区块链创新智能合约套件,基于Solidity构建,集成去中心化金融、数字藏品、链上治理、数据存储、安全工具等多元功能,支持多链适配,为Web3应用提供开箱即用的模块化合约与工具代码。 | language: Solidity | stars: 0 | forks: 0 | updated 2026-07-29T08:11:26Z | pushed 2026-07-29T08:09:08Z
cerqwq/ai-security
AI Security - AI安全工具 | language: Python | stars: 0 | forks: 0 | updated 2026-06-06T21:45:05Z | pushed 2026-06-06T21:45:01Z
yijinglab/LinuxEnvConfig
Ubuntu/Kali Linux基础环境与安全工具自动化配置脚本 | language: Shell | stars: 2 | forks: 4 | updated 2026-07-18T08:33:31Z | pushed 2026-06-03T09:11:06Z
2117252926/VulnSentry
智能安全工具调用平台 - 统一工具接口→工具注册→调度引擎→组合执行 | language: HTML | stars: 0 | forks: 0 | updated 2026-07-13T12:40:10Z | pushed 2026-06-08T13:47:28Z
doudou0308/agent-docker-tools
基于 Kali Linux 的 AI 驱动 Docker 环境。预装 30+ 安全工具开箱即用 | language: Dockerfile | stars: 1 | forks: 0 | updated 2026-06-08T14:57:41Z | pushed 2026-06-08T14:56:39Z
flclash-us/privacy-tools-m82tv7
隐私保护与安全工具集 - 广告拦截、DNS加密、防追踪、密码管理全攻略 | language: HTML | stars: 0 | forks: 0 | updated 2026-06-10T00:56:15Z | pushed 2026-06-10T00:56:11Z | homepage: https://flclash-us.github.io/privacy-tools-m82tv7/
flclash-us/privacy-tools-qwa841
隐私保护与安全工具集 - 广告拦截、DNS加密、防追踪、密码管理全攻略 | language: HTML | stars: 0 | forks: 0 | updated 2026-06-11T02:06:31Z | pushed 2026-06-11T02:06:27Z | homepage: https://flclash-us.github.io/privacy-tools-qwa841/
tinylion1024/oh-my-security
Oh-My-Security 是一款专为个人开发者、Indie Hackers 和自媒体创作者打造的轻量级终端安全工具。 我们不谈枯燥的企业级 DevSecOps 和等保合规,我们只关心关系到超级个体“身家性命”的切身痛点: 如何防止不小心把 API Key 传到 GitHub 导致破产?如何防止刚写好的文章因为包含敏感词被平台封号?如何防止自己刚上线的小工具站被羊毛党刷爆服务器? OMS 将顶级安全专家的知识库和 AI 审计能力封装进...
flclash-us/privacy-tools-iepsy3
隐私保护与安全工具集 - 广告拦截、DNS加密、防追踪、密码管理全攻略 | language: HTML | stars: 0 | forks: 0 | updated 2026-06-16T02:12:38Z | pushed 2026-06-16T02:12:37Z | homepage: https://flclash-us.github.io/privacy-tools-iepsy3/
shuhuNB515/KubeVigil
(基于 eBPF 的 K8s 运行时安全卫士),KubeVigil 是一款专为 Kubernetes 环境打造的轻量级、高性能运行时威胁防御框架。传统的云原生安全工具往往局限于静态镜像扫描或离线配置审计,面对利用 0day 漏洞的动态攻击、无文件内存马或逃逸行为往往无能为力。 KubeVigil 依托 eBPF 技术,直接在 Linux 内核态进行“降维打击”。它以极低的性能损耗,实时挂载并监听系统调用,精准捕获容器内的非法进程执行、越...