Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permissio
CVE-2026-4265;2d5e81bb83d5b5e5a7e1c330656076ae;Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in...
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User
CVE-2026-25783;956f96a4343be12ed12d8fec09b5cb86;Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cau...
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with mu
CVE-2026-24458;da84154b09231c2686de8bdcb88958b4;Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU...
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a manipulation of the argument Home can lead to s
CVE-2026-4237;5e5de09fbf90992b721442e65e282dbb;A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a ...
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve rem
CVE-2026-2462;924a21476eaa238ce8d850c6337d03b7;Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which al...
Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deleti
CVE-2026-2578;2acf2c6fbbc7635390e589ae1d28e9f7;Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read...
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fix
CVE-2025-69246;3671bc78842107c36b9dfd40be97ac39;Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throt...
Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated victim, results in arbitrary JavaScript execution in
CVE-2025-69245;cc6210d494928b5a7dd4589788240d8b;Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated vict...
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. Thi
CVE-2025-69243;fbca602b42ac237819802d3c10d0740b;Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enab...
Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim抯 browse
CVE-2025-69242;7b045f89d4b96fa6ec80b035444b5fae;Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbi...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
GruffTarsier463/express-starter-kit
🚀 Kickstart your web project with this production-ready Express.js starter kit featuring authentication, PostgreSQL, and built-in security tools. | topics: api, babel, backend, boilerplate, database, database-configurati...
mutiemaithya/express-starter-kit
🚀 Build robust applications with this production-ready Express.js starter kit featuring authentication, PostgreSQL support, and essential security tools. | topics: appengine, chai-http, database-configuration, dotenv, es...
Hossam1993591/NuVet
🔍 Scan .NET applications for vulnerabilities in NuGet dependencies, ensuring secure and reliable software with this professional-grade security tool. | topics: automation, csharp, dependency-management, dependency-scanni...
ahmedabbazi/linux-defender
🛡️ Protect Linux servers with Linux Defender, an open-source tool that simplifies security management through a unified interface for multiple security tools. | topics: android, ansible-role, asm, c, cent-os, centos, cis...
logan-agunat/Network-Security-Tool-Project
language: Python | stars: 0 | forks: 0 | updated 2026-03-20T02:04:57Z | pushed 2026-03-20T02:04:54Z
ahmedmagdy0000/NORD
🛡️ Protect your system with NORD, an enterprise-grade security tool for Parrot OS, offering real-time monitoring and vulnerability scanning. | topics: color-palette, color-scheme, color-theme, colors, colorscheme, custom...
navin-hariharan/CVE-DATABASE
🛡️ Complete & up-to-date CVE Database 🔍 | Track, search & analyze all known vulnerabilities ⚠️ | Power your security tools & stay protected! 🚀 | topics: cve, cve-scanning, cve-search, cvssv4, nmap, nvd-api, vulnerability...
Ed1s0nZ/CyberStrikeAI
CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, role-based testing with predefined security roles, a skills system with special...
ceasarwadud/secure-infrastructure-siem-wazuh
🔒 Design a secure network infrastructure with real-time threat detection using Wazuh SIEM, GNS3, and advanced security tools for optimal protection. | topics: cybesecurity, ethical-hacking, exploitation, hacking, kali-li...
Ahmedsofteng/red-team-arsenal
🎯 Empower red team operators with a toolkit of essential offensive security tools for effective penetration testing and threat simulations. | topics: aggressorscripts, blueteam, cammera-jammer, ethicalhacking, exploitati...