github-actions[bot]
394426a532
docs: 更新 1 篇文章 - 普华PowerPMS /Plan/BatchHandleFeedBackRecord 鉴权绕过漏洞 [skip ci]
2026-08-16 09:32:15 +00:00
1a3b17d78f
Add ragflow-audit (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286) to Web APP section ( #84 )
...
* docs: append new books references to README 文章/书籍/教程相关 section
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com >
* Add ragflow-audit (CVE-2026-28797/CVE-2026-24770/CVE-2025-69286) to Web APP section
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com >
* Add SnowEyes Chrome extension (sensitive info detection) to tools section
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com >
2026-08-11 08:36:24 -04:00
东方有鱼名为咸 and GitHub
1933ebcf55
Add files via upload
2026-08-11 07:52:33 -04:00
东方有鱼名为咸 and GitHub
68da8bcaf4
Update README.md
2026-08-09 08:14:02 -04:00
github-actions[bot]
de0479d279
docs: 更新 1 篇文章 - 用友GRP-U8Cloud产品jmreport组件模块Freemarker模板SSTI致RCE漏洞分析 [skip ci]
2026-08-09 07:04:13 +00:00
7432ea5857
add latest books to README 文章/书籍/教程相关 section ( #83 )
...
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com >
2026-08-08 05:47:08 -04:00
东方有鱼名为咸 and GitHub
65f92010d5
Add files via upload
2026-08-08 05:37:20 -04:00
东方有鱼名为咸 and GitHub
55a052353d
Add files via upload
2026-08-08 01:05:02 -04:00
东方有鱼名为咸 and GitHub
8dd4bd1172
Add new resources and links in README
...
Updated the README to include additional resources and links related to FastJson and Spring Framework vulnerabilities.
2026-08-02 03:02:44 -04:00
东方有鱼名为咸 and GitHub
6602db5059
Add files via upload
2026-08-02 02:59:00 -04:00
东方有鱼名为咸 and GitHub
0d4818c01b
Update FastJson2 section in README
2026-08-02 01:59:24 -04:00
东方有鱼名为咸 and GitHub
210458c6cf
Add files via upload
2026-08-02 01:57:59 -04:00
东方有鱼名为咸 and GitHub
d7190f28b4
Add files via upload
2026-08-02 00:21:13 -04:00
东方有鱼名为咸 and GitHub
d492180482
Remove FastJson2 RCE analysis entry from README
...
add FastJson2 Hash 碰撞 RCE 分析与复现
2026-08-01 10:45:44 -04:00
东方有鱼名为咸 and GitHub
7bde93dbb1
add FastJson2 Hash 碰撞 RCE 分析与复现
2026-08-01 10:42:05 -04:00
东方有鱼名为咸 and GitHub
08be292dfd
Fix typos in vulnerability links in README.md
...
add CVE‑2026‑49176(Windows WalletService 本地提权漏洞) 的 本地缓冲区溢出(BOF)风格的 PoC/Exploit
2026-08-01 06:17:08 -04:00
github-actions[bot]
ef683709d3
docs: 更新 1 篇文章 - 金和OA C6 PlanGiveOut.aspx SQL注入漏洞+越权访问IDOR漏洞+XSS漏洞 [skip ci]
2026-07-30 02:46:32 +00:00
github-actions[bot]
bc8c6ce29b
docs: 更新 1 篇文章 - 用友U8Cloud extsystem.dst 接口SQL注入漏洞 [skip ci]
2026-07-27 03:38:34 +00:00
东方有鱼名为咸 and GitHub
170547ef4d
add 【Windows提取】CVE-2026-54121:利用 Certighost 漏洞伪造域控(Domain Controller)的证书,从而获得 域控级别的 Kerberos 身份,最终实现 完全接管整个 Active Directory 域
2026-07-25 00:29:46 -04:00
东方有鱼名为咸 and GitHub
189289e3e5
add RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
2026-07-23 09:24:50 -04:00
github-actions[bot]
d32962f55e
docs: 更新 1 篇文章 - Fastjson 1.2.83 默认配置下的远程代码执行RCE [skip ci]
2026-07-20 16:28:01 +00:00
东方有鱼名为咸 and GitHub
31091afe00
add Fastjson 1.2.68-1.2.83 版本默认配置在特定场景下的反序列化RCE实现
2026-07-20 12:24:04 -04:00
东方有鱼名为咸 and GitHub
61571b66d6
Update README.md
2026-07-18 22:24:14 -04:00
东方有鱼名为咸 and GitHub
bdef3cd74d
add wp2shell + lab
2026-07-18 11:12:27 -04:00
东方有鱼名为咸 and GitHub
70ddd575be
update wp2shell scripts
2026-07-18 06:26:04 -04:00
东方有鱼名为咸 and GitHub
6fb2c3e945
add CVE-2026-63030 + CVE-2026-60137: pre-authentication SQL injection in WordPress core via REST batch-route confusion.
...
CVE-2026-63030 + CVE-2026-60137: pre-authentication SQL injection in WordPress core via REST batch-route confusion.
2026-07-18 06:09:40 -04:00
github-actions[bot]
4686235f11
docs: 更新 1 篇文章 - 用友U8Cloud XChangeServlet SQL注入漏洞+XXE漏洞 [skip ci]
2026-07-16 14:05:54 +00:00
东方有鱼名为咸 and GitHub
1ba941cd85
Add Upload_Auto_Fuzz tool description to README
...
Added a new tool for automated testing of web upload interfaces to the README.
2026-07-15 09:10:34 -04:00
东方有鱼名为咸 and GitHub
8b90213e11
add 【Linux提权】 CVE‑2026‑46242(Bad Epoll)
2026-07-05 14:30:31 +08:00
9b887ce364
Bump requests in /vuln_pocs/exploit-tools/tp5-getshell ( #79 )
...
Bumps [requests](https://github.com/psf/requests ) from 2.31.0 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases )
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md )
- [Commits](https://github.com/psf/requests/compare/v2.31.0...v2.33.0 )
---
updated-dependencies:
- dependency-name: requests
dependency-version: 2.33.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-05 13:06:00 +08:00
Mehdi BOUTAYEB and GitHub
29ff1f0c29
Add Darkmoon ( #80 )
2026-07-05 13:05:23 +08:00
6693085677
Consolidate scattered CVE/exploit dirs and restore Markdown link format in README ( #78 )
...
* chore: consolidate CVE and exploit directories and update README links
* fix: revert README links from HTML anchors back to Markdown format
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
2026-07-04 15:42:15 +08:00
东方有鱼名为咸 and GitHub
5162375b66
Add files via upload
2026-06-28 21:12:11 +08:00
东方有鱼名为咸 and GitHub
71a8cd50b2
add 添加两款OSINT 工具sherlock和Aliens_eye
2026-06-28 19:22:56 +08:00
东方有鱼名为咸 and GitHub
87fce1581b
add NebulaPulsar:一个 Java/C# WebShell 漏洞利用与植入工具,作为 Alien 项目的概念验证(PoC),适用于安全研究与漏洞利用实验。
2026-06-28 19:01:52 +08:00
东方有鱼名为咸 and GitHub
aad3c030a1
add jadx-ai-mcp:为 Jadx 提供 MCP 扩展,使 AI 工具能够直接调用本地 Jadx 进行 APK/DEX 反编译、搜索与分析,是构建 AI 驱动逆向工作流的关键组件。
2026-06-28 18:58:52 +08:00
东方有鱼名为咸 and GitHub
95fbc64849
add freellmapi:一个免费 LLM API 聚合服务,提供兼容 OpenAI 的统一接口,可无缝调用多个免费大模型,非常适合个人项目、教学和快速原型开发。
2026-06-28 18:54:08 +08:00
东方有鱼名为咸 and GitHub
8b378b17e8
add 【Linux提权】CVE‑2026‑46331:packet_edit_meme
2026-06-28 18:49:39 +08:00
东方有鱼名为咸 and GitHub
622927a01f
add reverse-skill 一个面向逆向工程、渗透测试和安全研究的技能路由包,支持 AI 编码助手自动选择合适的工作流和工具链,涵盖 APK、二进制、JS、CTF 等场景。
2026-06-28 12:06:43 +08:00
东方有鱼名为咸 and GitHub
4023534e16
add Linux提权】CVE-2026-43503:(DirtyClone)
...
【Linux提权】CVE-2026-43503:(DirtyClone)是一个演示 Linux 内核 Dirty‑COW 类漏洞的新型本地提权 PoC,利用网络栈共享内存处理缺陷实现对只读页缓存的非法写入并获取 root 权限。
2026-06-27 16:27:56 +08:00
东方有鱼名为咸 and GitHub
4e4cc626d8
RootHawk:整合多种已公开本地提权漏洞(如 Dirty Pipe、PwnKit、Polkit 3560 等)的一键化 Linux 提权检测与利用工具。
2026-06-27 10:31:57 +08:00
github-actions[bot]
e0be4cbe8f
docs: 更新 1 篇文章 - LiteLLM v1.84.0 安全漏洞完整分析报告 [skip ci]
2026-06-23 15:13:26 +00:00
github-actions[bot]
f272eddfd7
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 admin/Upload/upload 文件上传漏洞 [skip ci]
2026-06-18 04:39:59 +00:00
github-actions[bot]
b65bff0d09
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 admin/secret/edit SQL注入漏洞 [skip ci]
2026-06-17 04:46:01 +00:00
github-actions[bot]
28b86725d2
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 clearUserDevice SQL注入漏洞 [skip ci]
2026-06-16 05:01:18 +00:00
github-actions[bot]
59a9430855
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 downloadSharedFile 任意文件读取漏洞 [skip ci]
2026-06-15 05:01:01 +00:00
github-actions[bot]
e36ed50007
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 getFileTrueAddress SQL注入漏洞 [skip ci]
2026-06-14 04:46:07 +00:00
github-actions[bot]
2f610f2513
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 Pan/Upload/upload 文件上传漏洞 [skip ci]
2026-06-13 04:18:37 +00:00
github-actions[bot]
9c933719f8
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 uploadMultipleFile 任意文件上传漏洞 [skip ci]
2026-06-12 04:39:43 +00:00
9ec7b9ce02
Add BishopFox CVE-2026-34908-check to README.md ( #77 )
...
* Add Drun1baby/FineReportExploit to README.md next to existing FineReportExploit link
* Differentiate Drun1baby/FineReportExploit as Python tool next to Go tool in README.md
* Differentiate FineReportExploit implementations (Go vs Python) in README.md
* Add BishopFox CVE-2026-34908-check to README.md under IOT Device&Mobile Phone section
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
2026-06-11 20:56:28 +08:00