Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
oscerd/CVE-2026-48203
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0) | topics: apache-came...
ayyy7128/CVE-2026-43499-jinghu
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra) | language: C
CerberusMrXi/CVE-2026-48909-Joomla-SP-Exploit
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie deserialization to write webshell via Joomla FormattedtextLogger gadget chain....
oscerd/CVE-2026-47323
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.1...
J4ck3LSyN-Gen2/CVE-2026-58457
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educatio...
Ch4120N/CVE-2026-55579
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies. | topics: cve, cve-2026, cve-2026-55579, cwe-798, cwe-9...
CerberusMrXi/WP-Contest-Gallery-28.1.4-Exploit
Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and r...
justsoman/CVE-2026-43499-jinghu
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
hakaioffsec/CVE-2026-40083
SQL Injection at Cacti | language: Python
bibotai/secveri-cve-2026-50011-negative
language: Java
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
WAjkl/pentest-gui
16 个渗透测试工具的集成 GUI 平台,一键安装,开箱即用 | topics: chinese, nuclei, pentest, python, security-tools, thinker, vulnerability-scanner | language: Python | stars: 1 | forks: 0 | updated 2026-07-22T09:54:15Z | pushed 2026-07-17T19:38:...
Alyssa-syx/ai-autonomous-lab-hydrogen-demo
一个基于 AI 自主闭环控制的 DS 双电解池氢渗透实验演示项目 | stars: 0 | forks: 0 | updated 2026-07-22T16:20:05Z | pushed 2026-07-22T16:17:50Z
RainmeoX/Web-Security-Learning
网络安全学习项目 | Web 安全知识整理与实践 | 渗透测试、漏洞分析、安全防护 | topics: cybersecurity, learning, penetration-testing, security, web-security | language: Python | stars: 1 | forks: 0 | updated 2026-07-23T02:36:02Z | pushed 2026-07-23T02:35:5...
0zbq/PenetrationTesting_StudyNotes
这是一个用于存放我学习渗透测试时笔记的仓库 | stars: 0 | forks: 0 | updated 2026-07-23T03:53:19Z | pushed 2026-07-23T02:07:10Z
keecth/FakeCryptoJS
CryptoJS常规加解密自吐密钥、加解密方式,快速定位加解密位置(无视混淆)。SRC和常规渗透神器 | language: Python | stars: 624 | forks: 77 | updated 2026-07-23T07:02:37Z | pushed 2026-07-20T10:28:15Z
Aumddd/PentestReportGenerator
Pentest Report Generator 是一个全栈自动化渗透测试报告生成系统。 | language: Python | stars: 0 | forks: 0 | updated 2026-09-02T20:19:57Z | pushed 2026-09-02T20:07:41Z
shyrel666/RustForge
面向初学者的 AI 引导式 Web 渗透测试学习桌面应用:MITM 抓包代理 + AI 漏洞分析 + 渗透任务树 + OWASP/CWE 知识库。 | topics: ai-agents, pentesting, rust, security, security-tools, vulnerability-analysis, web-security | language: Rust | stars: 0 | forks: 0 | upd...
an7ln/wmpf-mcp-bridge
ai渗透测试小程序 | language: TypeScript | stars: 101 | forks: 14 | updated 2026-07-24T01:37:03Z | pushed 2026-07-18T09:55:13Z
CuriousLearnerDev/Online_Tools-AI
一个面向 Web 版桌面 安全测试的 AI Agent 平台,集成侦察、分析、规划、工具调用与反馈学习,实现自主完成渗透测试工作流An AI Agent platform for web-based security testing, integrating reconnaissance, analysis, planning, tool orchestration, and feedback-driven learning to au...
yuanweipeifang/AgentSec-RedTeam-Lab
研究智能体红队技术与生态治理,自建红队智能体进行安全渗透 | language: Python | stars: 0 | forks: 0 | updated 2026-08-06T02:23:41Z | pushed 2026-08-06T02:23:32Z