Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Billy-Ellis/exr-imageio-poc
PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5 | language: Python
rohit-sundar/cve-2026-23744
language: Python
0xmrma/CVE-2026-46558
Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user read, copy, delete, and overwrite assets in other workspaces.
0xmrma/CVE-2026-45806
Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because attacker-controlled URLs crossed into a redirect-following server fetch path without ...
0xmrma/CVE-2026-42089
A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed without user confirmation, turning attacker-controlled project metadata int...
0xmrma/CVE-2026-34207
The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets.
0xmrma/CVE-2026-34213
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
0xmrma/CVE-2026-34212
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
0xmrma/CVE-2026-33146
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
izxci/CVE-2026-54807
CVE-2026-54807 WooCommerce Privilege Escalation ║ ║ Unauthenticated Admin Role Assignment via Reg. Form | language: Shell
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
riankellyjn-a11y/publicdns-resolvers
Continuously validated public DNS resolver list sourced from publicdns.info. Updated daily. Drop-in replacement for stale public-dns.info resolver lists used by OSINT and security tools. | language: Python | stars: 0 | f...
xspeen/DIBOSER--RXC
🔐 The Diboser - Enterprise Terminal Security Tool for Termux | Password-protected terminal access with beautiful HTML-like popup UI | Advanced authentication, session management, and real-time monitoring | Protect your T...
DevFoxxx/OmniScan
OmniScan is a Python-based automated reconnaissance tool. It combines an intelligent wordlist generator with top-tier security tools like FFUF, Amass, WPScan, and Nmap into a single, sleek TUI. It streamlines the scannin...
bkhnaq/phising-triage-bot
An automated security tool designed to streamline phishing incident response. The bot automatically ingests reported emails, extracts suspicious indicators (URLs, Attachments, Headers), and performs real-time reputation ...
samyuthak-projects/password-security-tool
A Python tool that evaluates password strength using regex-based analysis and scoring logic, demonstrating key cybersecurity principles. | language: Python | stars: 0 | forks: 0 | updated 2026-03-20T18:07:55Z | pushed 20...
deveshkumar3668/phishing-URL-detector
A simple cyber security tool that detects potential phishing urls by analyzing https usage ,suspicious keywords and ip-based patters. | stars: 0 | forks: 0 | updated 2026-03-20T12:31:00Z | pushed 2026-03-20T12:30:57Z
Mus1shi/BYOD-Security-Posture-Monitor-for-Microsoft-365
PowerShell-based security tool that correlates device inventories across Microsoft Intune, Entra ID and Trend Vision One. The project aims to improve BYOD visibility, detect unmanaged or risky devices, and provide securi...
aashifm1/OSINT-framework
A security tool for Open Source Intelligence | topics: framework, osint | language: Python | stars: 0 | forks: 0 | updated 2026-03-22T12:01:41Z | pushed 2026-03-22T12:01:38Z
Albion-cmd/Albion-MYDFIR
Security tools, labs and portfolio documentation — Wilson Oluwasemiloore Elan | topics: bash, blue-teaming, cybersecurity-, penetration-testing, python, security-tools | language: Shell | stars: 2 | forks: 0 | updated 20...
AnandBinuArjun/CODEX-CYEBRSTIKE
a high-performance, AI-native security orchestration platform designed for modern Red Teams and Security Operations Centers (SOC). It bridges the gap between deep-reasoning AI models and enterprise-grade security tools (...