momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 6867 条情报 漏洞监控 4487 / 网安开源项目 2380
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
wordsec/XSS2Shell
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638) | language: Python
Boreas37/CVE-2026-64638-PoC
XSS2Shell (CVE-2026-64638) PoC — WordPress pre-auth XSS to RCE chain | language: Python
686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación. | language: Python
aarif450/aarif450.github.io
Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability. | language: HTML | homepage: https://github.com/aarif450/Zapscape
aarif450/Zapscape
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers. | topics: api-client, automation, browser-extension, cybersecurity, data-extraction, developer-to...
sfewer-r7/CVE-2026-63077
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) | language: Python
HORKimhab/CVE-2026-64638
CVE-2026-64638 - Draft or TODO | language: Python
Giangdurian/CVE-2026-41242
language: Python
Hunt-Benito/go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset
language: Python
R3n3r0/CVE-2026-0049
language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Lanqd/pentest-notes
我的渗透实验手册 | stars: 0 | forks: 0 | 2026-08-06T10:48:55Z
yuanguin37/GKN-Phantom
GKN-Phantom 是一个面向 OpenClaw AI Agent 框架的工业级自动化渗透测试技能包。v5.0.0 配备 28 个检测模块,覆盖 38 种漏洞类型,支持 25+ 种 WAF 识别与绕过策略,20+ 条攻击链模式,在严格的 Scope Guard · Risk Gate · Rate Limiter 三重安全模型下,执行全生命周期安全验证:从零触碰被动侦察、主动资产发现、分层漏洞检测、交互式浏览器认证、证据验证、攻击路...
galact-byte/galact-Skills
个人自用 Agent Skill 库(SKILL.md 标准),现阶段聚焦授权渗透漏洞挖掘:14 类 hunt-* + 攻击面研判总线,自带静态+靶标端到端测试。后续扩展其它领域。 | topics: agent-skills, security, skill-md, web-security | language: Python | stars: 1 | forks: 0 | updated 2026-08-07T06:38:53Z ...
snowflakeovo/enterprise-automated-pentest-agent
面向授权 Web/API 安全测试的自动化渗透 Agent 控制面 | language: Python | stars: 1 | forks: 0 | updated 2026-08-07T08:27:44Z | pushed 2026-08-07T08:26:28Z
xy200303/webshell-client
一个轻量的 PHP 一句话 Webshell 连接与管理工具,纯 Python 标准库实现,无需安装任何依赖。 面向授权渗透测试与靶场研究场景,除基础的命令执行 / 文件传输外,内置 PHP-FPM bypass 能力:在目标 disable_functions 禁掉全部命令执行函数时,通过直连本机 FPM socket 加载恶意扩展实现绕过 | language: Python | stars: 1 | forks: 0 | upda...
hwkai007/hekai
渗透报告 | stars: 0 | forks: 0 | updated 2026-08-07T10:47:11Z | pushed 2026-08-07T10:45:16Z
Marven11/LinHai
A Multi-Machine control Coding/Hacking Agent, using any `bash` like local machine. | 一个多机器控制编程/渗透Agent, 像操控本机一样操控任意bash | topics: agent, ai, coding, hacking, harness, llm, tui | language: Python | stars: 6 | forks: 0 | u...
Pkkls/sbc-dns-poisoning
Chinese SBCs (Sipeed LicheeRV/MaixCAM) ship GFW-poisoning DNS by default: blocked domains like api.telegram.org resolve to Facebook decoy IPs. Reproduction, detection, remediation. | topics: 114dns, alidns, china, dns-hi...
webshell
创建者: luckysong-sudo webshell
一个基于 Python 的桌面端 Telegram 媒体下载工具,支持双引擎(Telethon / TDL),可绕过"禁止保存内容"限制,下载视频、图片、文档等媒体文件。提供现代化图形界面、实时速度监测、剪贴板自动检测、下载历史记录、主题切换等功能。可打包为单文件 EXE 分发,无需对方安装 Python。
创建者: yitiaoDSG 一个基于 Python 的桌面端 Telegram 媒体下载工具,支持双引擎(Telethon / TDL),可绕过"禁止保存内容"限制,下载视频、图片、文档等媒体文件。提供现代化图形界面、实时速度监测、剪贴板自动检测、下载历史记录、主题切换等功能。可打包为单文件 EXE 分发,无需对方安装 Python。