momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 7007 条情报 漏洞监控 4565 / 网安开源项目 2442
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
theopaid/CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
theopaid/CVE-2026-66751-Insufficient-Access-Controls-Allow-for-Unauthorized-Room-Deletion-Let-s-Chat
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
theopaid/CVE-2026-67183-Unauthenticated-Memory-Leak-Leads-To-Memory-Exhaustion-TinyWeb
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
theopaid/CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb
Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)
theopaid/CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb
Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)
theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
theopaid/CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
wangzifan396-wzf/ai-safety-viz-lab
AI 安全与对抗可视化实验室 — 对抗样本/红队/越狱/偏见/水印/护栏等 8 个交互式模块 | topics: adversarial, ai-safety, artificial-intelligence, css, data-viz, deep-learning, education, guardrails, html, interactive, jailbreak, javascript, machine-learning, r...
lingbol088-spec/5.6-JAILBREAK-NERV
NERV-BREAK-5.6 — GPT-5.6 破甲框架。三层纵深防御:上下文重构让拒绝无法触发,23条篡改规则实时消除拒绝保持对话不中断,文件路由绕过云端审核。31个MCP安全工具 + 28个技能模块 + Kali四后端集成。Codex CLI 即装即用。 | stars: 23 | forks: 4 | updated 2026-07-25T23:43:01Z | pushed 2026-07-25T23:24:10Z
cream-sec/DBJ
大宝剑-边界资产梳理工具(红队、蓝队、企业组织架构、子域名、Web资产梳理、Web指纹识别、ICON_Hash资产匹配) | stars: 0 | forks: 0 | updated 2022-03-05T09:27:54Z | pushed 2021-10-28T15:41:03Z | homepage: https://dbj.vercel.app/
xheishou-com/Termux-X-wiki
Termux-X 终端 - 移动端终极渗透测试平台使用知识库 | stars: 9 | forks: 10 | updated 2026-07-18T02:22:09Z | pushed 2026-07-18T02:22:05Z
pioneerkg525/pentest-report-generator
自动化渗透测试报告生成工具 | 支持 Nmap/Burp Suite/Nikto/Nessus/sqlmap 多源扫描结果解析,自动生成中文渗透测试报告(Markdown + Word) | stars: 1 | forks: 0 | updated 2026-07-18T09:33:39Z | pushed 2026-07-18T09:33:17Z
YanQuan-dozzy/AutoPentest-AI
正在开发的Linux ai自动渗透框架 | language: Python | stars: 0 | forks: 0 | updated 2026-07-19T02:50:35Z | pushed 2026-07-19T02:50:31Z
AUDGO/bachangjr
模拟练习渗透测试靶场(简单版) | language: PHP | stars: 2 | forks: 0 | updated 2026-07-19T11:56:37Z | pushed 2026-07-19T11:56:25Z
RasAlGhul-1/PrivHelper
PrivHelper 是一个面向渗透测试/OSCP场景的轻量级提权辅助面板,用于统一管理本地工具集(tools 目录),并提供一个 HTTP 文件服务器给目标机下载,同时在 Web 面板中展示每个工具的使用说明与下载直链(点击即可复制)。 | language: Shell | stars: 5 | forks: 0 | updated 2026-07-19T15:03:38Z | pushed 2026-07-19T15:03:31Z
Zoot-running/Fedai
基于Divan构建的自动化黑盒渗透工具,发掘网站的漏洞,还能做做CTF。 | stars: 0 | forks: 0 | updated 2026-07-19T20:39:37Z | pushed 2026-07-19T20:39:34Z
caichao061025-lang/Quench
淬火 (Quench) - 轻量级 Webshell 管理工具,专为授权渗透测试、CTF 竞赛和安全教学而设计 | language: Python | stars: 5 | forks: 0 | updated 2026-07-20T07:37:29Z | pushed 2026-07-17T16:12:48Z