Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
sirconscious/vulnerable_php_code
A deliberately insecure PHP web application used to test and benchmark AI-powered code security analysis tools. Contains: SQL Injection, XSS, RCE, Path Traversal, File Upload bypass, IDOR, hardcoded credentials, and debu...
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink receive
CVE-2026-32724;579735197416c21029858a5cc19f2b20;PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused...
h3raklez/CVE-2025-31722
CVE-2025-31722 — Jenkins Templating Engine RCE | language: Python
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import funct
CVE-2026-3227;93b665ea2cf36c62e0fdd7f9bf1c4479;A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS co...
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor
CVE-2026-32720;1f1ebce1c30ee5f85431996817e85124;The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to...
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/
CVE-2026-32719;13a875f83189578ec355b7f1188b9eed;AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.import...
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT
CVE-2026-32717;f4bc545869fdb5db9b79aa4b1a8175f5;AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, Anyth...
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, w
CVE-2026-32715;ab30f7c4c9ce2ebbf0744dda605a6257;AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-pr...
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and Wr
CVE-2026-32713;00bb18906d4b8cac61052e9a005aa12f;PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (...
joshuavanderpoll/CVE-2026-3891
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC | topics: cve, cve-2026-3891, exploit, exploits, pentest-tool, pentesting, python, rce, security, security-tools, vulnerabilities, ...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
fkie-cad/GeMU
GeMU, the generic malware unpacker based on QEMU | language: C | stars: 24 | forks: 1 | updated 2026-03-16T12:39:36Z | pushed 2026-03-16T12:39:31Z
Gayathri-Jayan/Cybertrace_malware
language: Python | stars: 0 | forks: 0 | updated 2026-03-16T12:45:22Z | pushed 2026-03-16T12:45:19Z
Carl46436/PrankMalware
language: HTML | stars: 0 | forks: 0 | updated 2026-03-16T12:45:48Z | pushed 2026-03-16T12:45:44Z
FabioZolin/Malware_Analysis
Repository containing malware analysis and execution in a home lab | stars: 0 | forks: 0 | updated 2026-03-16T12:45:50Z | pushed 2026-03-16T12:45:46Z
aelumus/CyberScan-Portal
Malware detection portal with ML models, Docker, and CI/CD | language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-16T12:47:31Z | pushed 2026-03-16T12:47:27Z
Tagoletta/Malware-Report
language: HTML | stars: 0 | forks: 0 | updated 2026-03-18T20:21:33Z | pushed 2026-03-18T20:21:28Z
Techdokta/sa-ctex-dashboard
SA-CTEX — South African Cyber Threat Exchange | National Malware Readiness Platform | language: HTML | stars: 0 | forks: 0 | updated 2026-03-16T12:50:27Z | pushed 2026-03-16T12:50:23Z
juwad65/npm-malware-scanner
🛡️ Scan GitHub repositories and local projects for malicious npm packages in `package.json` files with this efficient and powerful command-line tool. | topics: npm | language: Go | stars: 0 | forks: 0 | updated 2026-03-1...
ShadowWhisperer/IPs
IP block lists for: Malware, Bots, scanners, etc. | topics: blocklist, botnet, brute-force, bruteforce, cnc, compromised, fail2ban, filter, firewall, hackers, ip, ips, ipset, iptables, malware, scanners, security | stars...
LudwiGRSA/Malware-IOCs
This is a repository containing malware IOCs and any other cool IOCs that I can find and share, enjoy! | stars: 0 | forks: 0 | updated 2026-03-16T12:53:05Z | pushed 2026-03-16T12:53:01Z