momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 10670 条情报 漏洞监控 6216 / 网安开源项目 4454
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
uziii2208/CVE-2026-86259
OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass | language: TypeScript
nightcorefan94/calculator.exe
CVE-2026-87491+CVE-2026-87491 exploit kit for v8 (example launches calculator.exe)
ymh001/meizu21-ghostlock-root
MEIZU 21 locked-bootloader runtime root via CVE-2026-43499 and KernelSU late-load | topics: android, cve-2026-43499, ghostlock, kernelsu, meizu21, root | language: Shell
erberkan/CVE-2026-60004-PoC
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | language: Python | homepage: https://blog.gitea.com/release-of-1.27.1/
uziii2208/CVE-2026-88899
Knowns 0.30.0: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem | language: Python
Bobikl/CVE-2026-43499-T807D
T807D CVE-2026-43499 research project | language: C
Shirouuu/Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526
PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git objects. Educational use only. | language: Shell
newazbenalam/Root-My-Galaxy-Payloads
CVE-2026-43499 root payloads feed for Root-My-Galaxy | language: C
yolkfull/cve-2026-52910-poc
POC of cve-2026-52910 | language: C
34zY/CVE-2026-72898
CVE-2026-72898 exploit | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Personfun/security-learning-notes
个人安全学习笔记。涵盖红蓝对抗、靶场实战、内网渗透、应急响应与代码审计。 | topics: blue-team, ctf, cybersecurity, notes, penetration-testing, red-team, security | stars: 1 | forks: 0 | updated 2026-09-27T07:24:13Z | pushed 2026-09-27T07:24:10Z
Neura0721/ctf-writeups
渗透测试实战 Writeup完整攻击链复盘 | topics: ctf, penetration-testing, security, writeups | stars: 0 | forks: 0 | updated 2026-09-15T07:03:02Z | pushed 2026-09-15T06:56:16Z
xiaoxixi222/ai-battle
赛博夺权战 - AI操作系统控制权攻防竞技平台 | language: Python | stars: 0 | forks: 0 | updated 2026-09-13T10:53:53Z | pushed 2026-09-13T10:53:50Z
EziosFamily/radio-adv-platform
网电空间对抗性攻防算法验证平台 | language: Python | stars: 0 | forks: 0 | updated 2026-09-13T11:47:44Z | pushed 2026-09-13T11:47:43Z
Yuki-0414/network-protocol-attack-defense-lab
基于Scapy完成ICMP伪造、SYN‑Flood、TCP‑RST攻防复现 | language: Python | stars: 0 | forks: 0 | updated 2026-09-14T01:39:42Z | pushed 2026-09-14T01:39:38Z
g0dxing/Red_Game
一个功能完整的网络安全攻防演练平台,采用红黑色调主题设计,支持实时态势感知、队伍管理、靶标部署、成绩统计等完整功能。"蓝的世界于凌晨两点沉入梦境,红的天地在此刻悄然迎来黎明。" | language: HTML | stars: 17 | forks: 1 | updated 2026-09-14T04:18:13Z | pushed 2026-09-14T04:18:09Z
haoliyang/PhishDrill
PhishDrill 是一套零第三方依赖的开源钓鱼演练平台:不用搭 C2、不用买商业平台,一台内网机器(甚至一台笔记本)即可完成「发信 → 埋点 → 去伪 → 归因到人 → 报表交付」的完整钓鱼攻防测试,并提供浏览器管理控制台与实时态势大屏。 | language: Python | stars: 10 | forks: 0 | updated 2026-09-18T00:41:37Z | pushed 2026-09-13T01:50...
HLRJ/cybersec-0to1-lab
中文网络安全攻防 0→1 实战课程:Build → Break → Trace → Fix → Detect | language: Python | stars: 0 | forks: 0 | updated 2026-09-20T09:35:55Z | pushed 2026-09-21T07:40:50Z
CavanasD/ThesisDrive
电子科技大学一年级新生创新项目——”网盘攻防战“——“睡前一杯栈溢出”小组项目(Thesis Drive)仓库 | topics: clouddrive, confidential, uestc | language: Vue | stars: 4 | forks: 1 | updated 2026-09-23T05:04:06Z | pushed 2026-09-23T05:03:51Z
guaidao2/rust-loader
简单的红队shellcode加载器 | language: Rust | stars: 0 | forks: 0 | updated 2026-09-14T03:15:52Z | pushed 2026-09-14T03:15:48Z