Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
VadlaReddySai/cve-writeups
Multiple CVEs (CVE-2026-38934, CVE-2026-38935, CVE-2026-38936) discovered in diskover-community including CSRF and XSS vulnerabilities with proof-of-concept and impact analysis.
HudzaifahArrantisi/CVE-2026-8181
CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan integration and modern GUI. | topics: cve-2026-8181, cve-scanning, python, wordp...
Linuxoid-cn/CVE-2026-43499-Poc-Analysis
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only. | language: C
musana/CVE-2026-15706
will be published
konzeptplus-gmbh/sppb
SP PAGEBUILDER-FIX-CVE-2026-48908
oscerd/CVE-2026-46457
Reproducer for CVE-2026-46457 — Apache Camel camel-nats inbound header injection (Camel control-header injection via a NATS publisher; CamelHttpUri -> SSRF) | topics: apache-camel, cve, proof-of-concept, security, vulner...
Windows Media 远程执行代码漏洞
GitHub Copilot 和 Visual Studio Code 安全功能绕过漏洞
Visual Studio 远程执行代码漏洞
Microsoft Office 信息泄露漏洞
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
collections
创建者: Hecate1337-py
collections
基于 Flask、JavaScript 与 DeepSeek API 开发智能代码审查系统,支持 Python、JavaScript、Java 代码上传和在线分析;通过正则规则与本地静态检测识别危险函数、硬编码密钥、异常处理不规范等问题,并结合大模型完成逻辑漏洞、安全风险、性能及可维护性分析;实现统一结果校验、问题合并、代码评分、可视化统计、报告筛选与 JSON/PDF 导出,同时设计 AI 超时、接口异常和无效 JSON 情况下的自动降级机制
创建者: plqyqh520-040910
基于 Flask、JavaScript 与 DeepSeek API 开发智能代码审查系统,支持 Python、JavaScript、Java 代码上传和在线分析;通过正则规则与本地静态检测识别危险函数、硬编码密钥、异常处理不规范等问题,并结合大模型完成逻辑漏洞、安全风险、性能及可维护性分析;实现统一结果校验、问题合并、代码评分、可视化统计、报告筛选与 JSON/PDF 导出,同时设计 AI ...
collection of webshells found online for security fuzzing
创建者: hqdudesec
collection of webshells found online for security fuzzing
红队指挥控制系统
创建者: Nutchies
红队指挥控制系统
SQL 注入自动化脚本-渗透项目/渗透工具/脚本文件
创建者: JY-666-YINZI
SQL 注入自动化脚本-渗透项目/渗透工具/脚本文件
Due to improper permission checks on the app server, attackers can trigger JNDI injection via the "loadTree" interface to achieve RCE (requires lower JDK versions). Legacy vuln, patched in August. EAS is also affected with a different path.**应用服务器权限验证不当,导致攻击者可以向loadTree接口执行JNDI注入,造成远程代码执行漏洞。利用该漏洞需低版本JDK。(漏洞比较旧,8月份补丁已出,**EAS也存在类似漏洞,只是路径不一样)
创建者: JY-666-YINZI
Due to improper permission checks on the app server, attackers can trigger JNDI injection via the "loadTree" interface to achieve RCE (requires lower JDK versions). Legacy vuln, patched in August. EAS i...
🚀
创建者: JY-666-YINZI
com.skypulse.weather
创建者: sunsanxingkong
LSPosed 模块 - 彩云天气 (
🚨
创建者: JY-666-YINZI
AI Agent 驱动的森林防火智能监测运维系统 | 六阶段 Agent 流水线 + FWI 火险评估 + 自动应急响应
创建者: LXY-hub11
AI Agent 驱动的森林防火智能监测运维系统 | 六阶段 Agent 流水线 + FWI 火险评估 + 自动应急响应