momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 7118 条情报 漏洞监控 4617 / 网安开源项目 2501
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Max78000/CVE-2026-27641-Flask-Reuploaded
PoC and test server | language: Python
pickl31/CVE-2026-59827
Metabase CVE-2026-59827 Vulnerability Scanner | language: Python
lucifer0xf/wp2shell-Wordpress-TOWN
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise. | la...
HORKimhab/CVE-2026-64600
CVE-2026-64600 - Draft - Check todo | homepage: https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt
dinosn/wp2shell-lab
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1 | topics: cve-2026-60137, cve-2026-63030...
ghostpels/CVE-2026-13001
language: Python
oscerd/CVE-2026-49365
PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.1...
007bsd/ml-kem-key-recovery
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2) | language: Python
oscerd/CVE-2026-53913
PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required roles/permissions the token is never verified, so any forged/garbage bearer token b...
huseyn0vs/CVE-2026-16540-SimplyScheduleAppointments
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion | language: Shell
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
txluck/secweb
🛡️ 自动化渗透测试调度平台 — Claude Code 生态. AI 驱动 / 多目标并发 / 动态 skill 加载 / 实时观测 | language: Python | stars: 11 | forks: 3 | updated 2026-07-10T15:26:01Z | pushed 2026-07-08T13:44:17Z
Gavin-crazyCoding/GavinFloat
**GavinFloat** 是一个 Android 悬浮球侧边栏应用,运行在 WindowManager 叠加层中。与 Termux 共享 `com.termux` 用户 ID,可直接操作 Termux 文件系统和发送命令到终端。提供 **35+ 图形化工具弹窗**,覆盖渗透测试、系统管理、文件编辑、网络工具、AI 对话、ADB 控制等场景。 | language: Java | stars: 1 | forks: 0 | updat...
Jialeiv/agent-injection-lab
Prompt injection 攻防实验台 · A reproducible lab for prompt injection in LLM agents (indirect injection, two-pillar defense, relay poisoning) | language: Python | stars: 1 | forks: 0 | updated 2026-07-08T05:04:52Z | pushed 20...
RedArmory/IoT-Botnet
这是一套用于网络攻防技术研究的物联网僵尸网络教学演示程序,由“控制端”和“被控端”组成,主要用于在封闭的虚拟机环境中模拟僵尸网络(Botnet)的工作原理。编写这份代码的目的,不是为了制造破坏,而是为了揭开黑盒。只有理解了攻击者的武器是如何锻造的,我们才能更好地铸造盾牌。 如果你是学生,请利用这份代码学好 TCP/IP;如果你是运维人员,请利用它来测试你的防火墙规则;如果你是开发者,请参考它的并发模型但不要抄袭它的恶意逻辑。 | top...
hsbroy/RedBlue_AI_Agent
實現紅藍方AI Agent攻防發現漏洞後提供防禦改進方向 | language: Python | stars: 0 | forks: 0 | updated 2026-07-09T04:58:01Z | pushed 2026-07-09T04:57:58Z
ssrsec/webstrike
WebStrike 是一套以 Chromium 系浏览器扩展(Manifest V3) 为受控端点的指挥与控制(C2)套件。与传统以进程/驱动为主的 C2 相比,其工作重心落在 浏览器安全域:在合规授权与攻防演练场景下,可显著降低与终端 EDR 在 进程注入、驱动、内核回调 等层面的直接对抗成本,同时将能力锚定在用户 真实访问的 Web 会话 上。 | language: Python | stars: 72 | forks: 21 |...
Gavinic/GenText-Forensics-ACM-MM-2026-Challange
stars: 0 | forks: 0 | 2026-07-08T12:19:56Z
guaidao2/XuanMu-RedTeam-Agent-Base-Z3r0
玄幕安全团队开源汉化和修改的无需docker可在Kali Linux上直接运行的红队AI agent。 | language: Python | stars: 2 | forks: 0 | updated 2026-07-14T06:21:52Z | pushed 2026-07-11T04:48:35Z
YichengYang-coding/ashare-style-rotation-2024
Factor-level forensics of the 2024H1 A-share rotation: crowded micro-cap unwind, regulatory repricing, and the dividend re-rating | topics: china-a-shares, event-study, factor-investing, quantitative-finance | language: ...
darkrelicz/dfir-dataset
language: Python | stars: 0 | forks: 0 | updated 2026-07-08T08:34:20Z | pushed 2026-07-08T09:29:09Z