Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
piiiico/mcp-check
MCP server security scanner — tests against clause-compliance vulnerabilities (arxiv 2603.10163), CVE-2026-26118, and common MCP security gaps | language: TypeScript
NFA regex engine NULL pointer dereference affects Vim < 9.2.0137
mdshoaibuddinchanda/ZOMBIE_GUARD
ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866) | topics: archive-evasion, archive-security, cve-2026-0866, cybersecurity, entropy-analysis, machine-learning, malware-detection, malware-re...
A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in c
CVE-2026-4163;dd061ec96eba6122b12642e7c4764b97;A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request ...
Jvr2022/CVE-2026-31802
PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory. | topics: cve, cve-2026-31802, exploit, node-tar, path-traversal,...
Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.
CVE-2026-4179;eaf1ba33fc481e3070e292f9d4b2fe3e
Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute a
CVE-2026-32774;96244f76b3b8dd7b3b723d107fb8fd38;Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can i...
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack exec
CVE-2026-0849;c2284f253d6ebc190de0cd5ccd73f14e;Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to co...
StillSoul/CVE-2020-15099
TYPO3 CVE-2020-15099 — Unauthenticated RCE | topics: cve-2020-15099, deserialization, pentest, php-object-injection, rce, typo3, typo3-cms | language: Python
StillSoul/CVE-2019-12747
TYPO3 CVE-2019-12747 — Unauthenticated RCE | topics: cve-2019-12747, deserialization, pentest, php-object-injection, rce, typo3, typo3-cms | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
nezzyomran/ExecEvasion
🛠️ Generate obfuscated commands to bypass WAFs easily with ExecEvasion, designed for pentesters and bug bounty hunters facing command injection challenges. | topics: backdoor, backdooring, backdoors, dynamic-analysis, ev...
IvanAchire/waf-for-gmssh
topics: anti-cc, gmssh, linux-security, lua, luajit, nginx, ngx-lua, openresty, waf, web-security | language: Lua | stars: 1 | forks: 0 | updated 2026-03-16T19:22:55Z | pushed 2026-03-16T19:22:52Z | homepage: https://iva...
ZEREX222/HttpWard
HttpWard is a lightweight, high-performance L7 reverse proxy written in Rust, focused on strong security (WAF, rate limiting, DDoS mitigation), intelligent caching, flexible virtual host routing, and extremely low resour...
Zidane109/cloud-honeypot-auto-block
🛡️ Automate detection and blocking of abusive IPs on AWS using honeypot data, Terraform, Lambda, and WAF for cloud security. | topics: aws, cloud-security, cloudwatch, devsecops, dynamodb, honeypot, infrastructure-as-cod...
primituga/OSIRIS
is a fast, terminal-based forensic URL analyzer. Instead of just relying on static databases, OSIRIS actively reaches out to suspicious links using WAF/Anti-Bot bypass techniques, extracts the raw source code, and dissec...
corazawaf/coraza
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library | topics: coraza, coraza-waf, coreruleset, go, golang, hacktoberfest, http, modsecurity, owasp, owasp-crs, waf, web-application-firewal...
ilyasaftr/coraza-envoy-waf
language: Go | stars: 0 | forks: 0 | updated 2026-03-16T19:38:07Z | pushed 2026-03-16T19:38:03Z
anujatappeta/sql_injection
A web security testing project demonstrating SQL injection vulnerability detection using sqlmap and analyzing how WAF protections affect automated attacks. | stars: 0 | forks: 0 | updated 2026-03-16T19:44:18Z | pushed 20...
akbarmaulaa/scaling-waffle
stars: 0 | forks: 0 | updated 2026-03-16T19:48:35Z | pushed 2026-03-16T19:48:31Z
cendrawasihdevnanda/congenial-waffle
stars: 0 | forks: 0 | updated 2026-03-16T19:49:10Z | pushed 2026-03-16T19:49:05Z