momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 10765 条情报 漏洞监控 6282 / 网安开源项目 4483
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
ZeroDayEvil/CVE-2026-20805-PoC
🛡️ Official AI Security Tool module for CVE-2026-20805 (Desktop Window Manager / dwm.exe Information Disclosure & Memory Leak Diagnostic). | topics: ai-security-tool, cve-2026-20805, windows-security
promasu/CVE-2026-73786
Might be used to share PoC and findings regarding CVE-2026-73786 in the future
cxlfhx/ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes | language: C
bahirul/cve-2026-86060
Mikrotik CVE-2026-86060 Score 9.2 Critical
squeeze440/inference-gateway-PoC
PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4). | language: Python
squeeze440/code-graph-rag-PoC
PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1).
squeeze440/crw-PoC
PoC — SSRF via JS-rendering tier bypass of the URL safety filter in crw (GHSA-5jp3-339h-vxqw, CVE-2026-87007, CVSS 7.5). | language: HTML
squeeze440/terrapod-PoC
PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).
squeeze440/linux-entra-sso-PoC
PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3). | language: JavaScript
squeeze440/tugtainer-PoC
PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc-6vc7-xrfh, CVE-2026-87004, CVSS 8.1). | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
渗透爬虫(shentou-crawler):多渠道公司线索采集框架——小红书/脉脉采线索 → 公司识别 → 企查查/天眼查/IT桔子工商查询 → 联系池双层Excel(找CFO/融资负责人)
创建者: heaventorn 渗透爬虫(shentou-crawler):多渠道公司线索采集框架——小红书/脉脉采线索 → 公司识别 → 企查查/天眼查/IT桔子工商查询 → 联系池双层Excel(找CFO/融资负责人)
AD CS 证书身份伪造漏洞,属于ESC(Exploit Certification)系列 的新成员
创建者: TryA9ain AD CS 证书身份伪造漏洞,属于ESC(Exploit Certification)系列 的新成员
一个将要开源的网络安全教学平台
创建者: taotieming 一个将要开源的网络安全教学平台
java反序列化自学习笔记
创建者: jielna999-sketch java反序列化自学习笔记
家庭双线宽带(电信+移动)接入点监测工具:分线连通性监控、掉线 IM 告警、引导式分线测速,全程绕过 clash TUN
创建者: striver2006 家庭双线宽带(电信+移动)接入点监测工具:分线连通性监控、掉线 IM 告警、引导式分线测速,全程绕过 clash TUN
LAB-RCE - 3 jalur Remote Code Execution (CWE-78 command injection, CWE-95 eval, CWE-434 upload webshell) - tugas kuliah keamanan web
创建者: ManuelKy08 LAB-RCE - 3 jalur Remote Code Execution (CWE-78 command injection, CWE-95 eval, CWE-434 upload webshell) - tugas kuliah keamanan web
ctkqiang/BountyOS
BountyOS 是一个只读的移动端漏洞赏金运营控制台,面向漏洞赏金猎人(Bug Bounty Researcher)。 它是一个原生 Android 应用,让研究者能在手机上查看并同步自己在 HackerOne、Bugcrowd 等平台上的数据。它不会提交、修改、删除、评论或对平台数据进行任何写入操作——BountyOS 只是一个查看与同步客户端,不是漏洞扫描器,不是 AI 助手,也不是赏金提交平台。 | topics: androi...
Fasthei/DSHAIred
AI红队平台 | stars: 0 | forks: 0 | updated 2026-09-07T16:35:00Z | pushed 2026-09-07T16:34:57Z
wj-0623/Agenttrust
AgentTrust 是面向 AI Agent 的运行时安全与评测控制面,在输入、外部上下文、工具执行前、工具结果和最终输出五个边界实施策略检查,并提供来源追踪、污点传播、MCP/A2A 防护、红队评测、人工审批、回滚和可复现发布证据。 | language: Python | stars: 1 | forks: 0 | updated 2026-09-08T06:46:21Z | pushed 2026-09-22T00:15:33Z
chencore/ai-agent-security-landscape
AI 智能体安全产品调研(电子围栏/防火墙/护栏/红队)——2026-09 市场深挖,文档中文 | stars: 0 | forks: 0 | updated 2026-09-08T09:47:25Z | pushed 2026-09-08T09:45:45Z