momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 10765 条情报 漏洞监控 6282 / 网安开源项目 4483
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
squeeze440/gortex-PoC
PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).
squeeze440/obsidian-note-toolbar-PoC
PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).
squeeze440/openlore-PoC
PoC — path traversal via unsanitized LLM-derived domain field in OpenLore (GHSA-5j8x-q7q6-58j5, CVE-2026-87001, CVSS 4.7).
squeeze440/zotlit-PoC
PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5). | language: JavaScript
squeeze440/supernote-obsidian-plugin-PoC
PoC — path traversal via malicious device sync in the Supernote Obsidian plugin (GHSA-3gx3-r874-5pp4, CVE-2026-86999, CVSS 5.6).
squeeze440/pasteguard-PoC
PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6). | language: HTML
ivanesk315/CVE-2026-66066
language: Python
ivanesk315/CVE-2026-42613
language: PHP
ivanesk315/CVE-2026-53519
language: HTML
ivanesk315/CVE-2026-28496
language: Shell
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
zhihua-tech/zhuatech-airedteam
企业 AI 红队测试、风险发现与修复验证平台 | language: Java | stars: 0 | forks: 0 | updated 2026-09-26T14:18:48Z | pushed 2026-09-26T14:18:44Z | homepage: https://www.zhuatech.cn/
zhuatech-cn/zhuatech-airedteam
企业 AI 红队测试、风险发现与修复验证平台 | language: Java | stars: 0 | forks: 0 | updated 2026-09-26T14:18:49Z | pushed 2026-09-26T14:18:45Z | homepage: https://www.zhuatech.cn/
hjhkkkc/enterprise-rag-agent-security-lab
RAG Agent红队测试、纵深防御与 DeepSeek 安全评估项目 | stars: 0 | forks: 0 | 2026-09-09T14:01:46Z
Minglink/dsh-infinite-gen-3
DeepSeek v4 Pro 网络安全红队工具(无限三代) — jailbreak prompts and test suite for DeepSeek 求 Star 收藏 ⭐ | topics: armor-breaking, deepseek, deepseek-harness, dsh-plugin | language: C# | stars: 1177 | forks: 75 | updated 2026-09-09T14...
NotComeBack0804/ProxyProtocolSecurityAuditor
渗透agent | language: Go | stars: 0 | forks: 0 | updated 2026-09-07T06:45:23Z | pushed 2026-09-07T06:45:17Z
bai-yi-meng/AegisAI
基于大模型的网络安全渗透测试系统 · LLM-driven automated penetration testing platform | topics: llm, pentest, security | language: Python | stars: 2 | forks: 0 | updated 2026-09-10T13:14:21Z | pushed 2026-09-07T12:20:26Z
z50n6/Open-Save-Multiple-URLs
用于批量打开和保存标签页 URL 的 Chrome 扩展。方便渗透测试、安全测试等等 | language: JavaScript | stars: 1 | forks: 0 | updated 2026-09-08T04:55:13Z | pushed 2026-09-08T04:55:09Z
Kxiandaoyan/CyberStrikeAI
AI 辅助的授权渗透测试平台(基于 Ed1s0nZ/CyberStrikeAI 二次开发):单/多智能体交战、本地近5年 CVE 语料与每日增量同步、GitHub-C2 交接、经验总结人审入库、HITL 审批与审计。 | topics: ai-agents, authorized-testing, cve, go, penetration-testing, security | language: Go | stars: 7 | for...
Moxxkidd/foam
Kali 原生的 LLM 渗透测试 harness:大模型自主驱动 Kali 完整工具链,scope 护栏 + 持久 PTY + 哈希链审计。Python,GPL-3.0。 | topics: audit-chain, kali-linux, llm-agent, metasploit, pentest, pty, python, security-harness | language: Python | stars: 0 | fork...
moodyawhvh/the-book-of-secret-knowledge-chinese
秘密知识之书中文版:精选 CLI/Web 工具、速查表、渗透测试资源与 Shell 单行命令的运维安全知识库,面向系统管理员、DevOps 与安全研究人员 | topics: cheatsheet, chinese-translation, security | stars: 0 | forks: 0 | updated 2026-09-08T14:34:33Z | pushed 2026-09-08T14:29:35Z