2029 Commits
Author SHA1 Message Date
github-actions[bot] 394426a532 docs: 更新 1 篇文章 - 普华PowerPMS /Plan/BatchHandleFeedBackRecord 鉴权绕过漏洞 [skip ci] 2026-08-16 09:32:15 +00:00
CopilotGitHubMr-xncopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
1a3b17d78f Add ragflow-audit (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286) to Web APP section (#84)
* docs: append new books references to README 文章/书籍/教程相关 section

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

* Add ragflow-audit (CVE-2026-28797/CVE-2026-24770/CVE-2025-69286) to Web APP section

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

* Add SnowEyes Chrome extension (sensitive info detection) to tools section

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-08-11 08:36:24 -04:00
东方有鱼名为咸andGitHub 1933ebcf55 Add files via upload 2026-08-11 07:52:33 -04:00
东方有鱼名为咸andGitHub 68da8bcaf4 Update README.md 2026-08-09 08:14:02 -04:00
github-actions[bot] de0479d279 docs: 更新 1 篇文章 - 用友GRP-U8Cloud产品jmreport组件模块Freemarker模板SSTI致RCE漏洞分析 [skip ci] 2026-08-09 07:04:13 +00:00
CopilotGitHubcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Mr-xn
7432ea5857 add latest books to README 文章/书籍/教程相关 section (#83)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-08-08 05:47:08 -04:00
东方有鱼名为咸andGitHub 65f92010d5 Add files via upload 2026-08-08 05:37:20 -04:00
东方有鱼名为咸andGitHub 55a052353d Add files via upload 2026-08-08 01:05:02 -04:00
东方有鱼名为咸andGitHub 8dd4bd1172 Add new resources and links in README
Updated the README to include additional resources and links related to FastJson and Spring Framework vulnerabilities.
2026-08-02 03:02:44 -04:00
东方有鱼名为咸andGitHub 6602db5059 Add files via upload 2026-08-02 02:59:00 -04:00
东方有鱼名为咸andGitHub 0d4818c01b Update FastJson2 section in README 2026-08-02 01:59:24 -04:00
东方有鱼名为咸andGitHub 210458c6cf Add files via upload 2026-08-02 01:57:59 -04:00
东方有鱼名为咸andGitHub d7190f28b4 Add files via upload 2026-08-02 00:21:13 -04:00
东方有鱼名为咸andGitHub d492180482 Remove FastJson2 RCE analysis entry from README
add FastJson2 Hash 碰撞 RCE 分析与复现
2026-08-01 10:45:44 -04:00
东方有鱼名为咸andGitHub 7bde93dbb1 add FastJson2 Hash 碰撞 RCE 分析与复现 2026-08-01 10:42:05 -04:00
东方有鱼名为咸andGitHub 08be292dfd Fix typos in vulnerability links in README.md
add CVE‑2026‑49176(Windows WalletService 本地提权漏洞) 的 本地缓冲区溢出(BOF)风格的 PoC/Exploit
2026-08-01 06:17:08 -04:00
github-actions[bot] ef683709d3 docs: 更新 1 篇文章 - 金和OA C6 PlanGiveOut.aspx SQL注入漏洞+越权访问IDOR漏洞+XSS漏洞 [skip ci] 2026-07-30 02:46:32 +00:00
github-actions[bot] bc8c6ce29b docs: 更新 1 篇文章 - 用友U8Cloud extsystem.dst 接口SQL注入漏洞 [skip ci] 2026-07-27 03:38:34 +00:00
东方有鱼名为咸andGitHub 170547ef4d add 【Windows提取】CVE-2026-54121:利用 Certighost 漏洞伪造域控(Domain Controller)的证书,从而获得 域控级别的 Kerberos 身份,最终实现 完全接管整个 Active Directory 域 2026-07-25 00:29:46 -04:00
东方有鱼名为咸andGitHub 189289e3e5 add RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0 2026-07-23 09:24:50 -04:00
github-actions[bot] d32962f55e docs: 更新 1 篇文章 - Fastjson 1.2.83 默认配置下的远程代码执行RCE [skip ci] 2026-07-20 16:28:01 +00:00
东方有鱼名为咸andGitHub 31091afe00 add Fastjson 1.2.68-1.2.83 版本默认配置在特定场景下的反序列化RCE实现 2026-07-20 12:24:04 -04:00
东方有鱼名为咸andGitHub 61571b66d6 Update README.md 2026-07-18 22:24:14 -04:00
东方有鱼名为咸andGitHub bdef3cd74d add wp2shell + lab 2026-07-18 11:12:27 -04:00
东方有鱼名为咸andGitHub 70ddd575be update wp2shell scripts 2026-07-18 06:26:04 -04:00
东方有鱼名为咸andGitHub 6fb2c3e945 add CVE-2026-63030 + CVE-2026-60137: pre-authentication SQL injection in WordPress core via REST batch-route confusion.
CVE-2026-63030 + CVE-2026-60137: pre-authentication SQL injection in WordPress core via REST batch-route confusion.
2026-07-18 06:09:40 -04:00
github-actions[bot] 4686235f11 docs: 更新 1 篇文章 - 用友U8Cloud XChangeServlet SQL注入漏洞+XXE漏洞 [skip ci] 2026-07-16 14:05:54 +00:00
东方有鱼名为咸andGitHub 1ba941cd85 Add Upload_Auto_Fuzz tool description to README
Added a new tool for automated testing of web upload interfaces to the README.
2026-07-15 09:10:34 -04:00
东方有鱼名为咸andGitHub 8b90213e11 add 【Linux提权】 CVE‑2026‑46242(Bad Epoll) 2026-07-05 14:30:31 +08:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
9b887ce364 Bump requests in /vuln_pocs/exploit-tools/tp5-getshell (#79)
Bumps [requests](https://github.com/psf/requests) from 2.31.0 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.31.0...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-05 13:06:00 +08:00
Mehdi BOUTAYEBandGitHub 29ff1f0c29 Add Darkmoon (#80) 2026-07-05 13:05:23 +08:00
CopilotGitHubcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
6693085677 Consolidate scattered CVE/exploit dirs and restore Markdown link format in README (#78)
* chore: consolidate CVE and exploit directories and update README links

* fix: revert README links from HTML anchors back to Markdown format

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-07-04 15:42:15 +08:00
东方有鱼名为咸andGitHub 5162375b66 Add files via upload 2026-06-28 21:12:11 +08:00
东方有鱼名为咸andGitHub 71a8cd50b2 add 添加两款OSINT 工具sherlock和Aliens_eye 2026-06-28 19:22:56 +08:00
东方有鱼名为咸andGitHub 87fce1581b add NebulaPulsar:一个 Java/C# WebShell 漏洞利用与植入工具,作为 Alien 项目的概念验证(PoC),适用于安全研究与漏洞利用实验。 2026-06-28 19:01:52 +08:00
东方有鱼名为咸andGitHub aad3c030a1 add jadx-ai-mcp:为 Jadx 提供 MCP 扩展,使 AI 工具能够直接调用本地 Jadx 进行 APK/DEX 反编译、搜索与分析,是构建 AI 驱动逆向工作流的关键组件。 2026-06-28 18:58:52 +08:00
东方有鱼名为咸andGitHub 95fbc64849 add freellmapi:一个免费 LLM API 聚合服务,提供兼容 OpenAI 的统一接口,可无缝调用多个免费大模型,非常适合个人项目、教学和快速原型开发。 2026-06-28 18:54:08 +08:00
东方有鱼名为咸andGitHub 8b378b17e8 add 【Linux提权】CVE‑2026‑46331:packet_edit_meme 2026-06-28 18:49:39 +08:00
东方有鱼名为咸andGitHub 622927a01f add reverse-skill 一个面向逆向工程、渗透测试和安全研究的技能路由包,支持 AI 编码助手自动选择合适的工作流和工具链,涵盖 APK、二进制、JS、CTF 等场景。 2026-06-28 12:06:43 +08:00
东方有鱼名为咸andGitHub 4023534e16 add Linux提权】CVE-2026-43503:(DirtyClone)
【Linux提权】CVE-2026-43503:(DirtyClone)是一个演示 Linux 内核 Dirty‑COW 类漏洞的新型本地提权 PoC,利用网络栈共享内存处理缺陷实现对只读页缓存的非法写入并获取 root 权限。
2026-06-27 16:27:56 +08:00
东方有鱼名为咸andGitHub 4e4cc626d8 RootHawk:整合多种已公开本地提权漏洞(如 Dirty Pipe、PwnKit、Polkit 3560 等)的一键化 Linux 提权检测与利用工具。 2026-06-27 10:31:57 +08:00
github-actions[bot] e0be4cbe8f docs: 更新 1 篇文章 - LiteLLM v1.84.0 安全漏洞完整分析报告 [skip ci] 2026-06-23 15:13:26 +00:00
github-actions[bot] f272eddfd7 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 admin/Upload/upload 文件上传漏洞 [skip ci] 2026-06-18 04:39:59 +00:00
github-actions[bot] b65bff0d09 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 admin/secret/edit SQL注入漏洞 [skip ci] 2026-06-17 04:46:01 +00:00
github-actions[bot] 28b86725d2 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 clearUserDevice SQL注入漏洞 [skip ci] 2026-06-16 05:01:18 +00:00
github-actions[bot] 59a9430855 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 downloadSharedFile 任意文件读取漏洞 [skip ci] 2026-06-15 05:01:01 +00:00
github-actions[bot] e36ed50007 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 getFileTrueAddress SQL注入漏洞 [skip ci] 2026-06-14 04:46:07 +00:00
github-actions[bot] 2f610f2513 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 Pan/Upload/upload 文件上传漏洞 [skip ci] 2026-06-13 04:18:37 +00:00
github-actions[bot] 9c933719f8 docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 uploadMultipleFile 任意文件上传漏洞 [skip ci] 2026-06-12 04:39:43 +00:00
CopilotGitHubcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
9ec7b9ce02 Add BishopFox CVE-2026-34908-check to README.md (#77)
* Add Drun1baby/FineReportExploit to README.md next to existing FineReportExploit link

* Differentiate Drun1baby/FineReportExploit as Python tool next to Go tool in README.md

* Differentiate FineReportExploit implementations (Go vs Python) in README.md

* Add BishopFox CVE-2026-34908-check to README.md under IOT Device&Mobile Phone section

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-06-11 20:56:28 +08:00