Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Wangs-official/opace6-cve-2026-64560
针对 OnePlus Ace6 设备的 cve-2026-64560 复现
yym8538/CVE-2026-30951
language: JavaScript
yym8538/CVE-2026-34220
language: JavaScript
AtlasVector/Kestra-cve-2026-53576
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common Docker-socket misconfiguration turns container-root into full host com...
0ch4/ghostlock-mrx-w09
CVE-2026-43499 (GhostLock) port: working root on the Huawei MatePad Pro MRX-W09 (Kirin 990, EMUI 11, Linux 4.14.116) - disassembly-proven write primitive, perf cred leak, and a source-derived HKIP bypass | topics: androi...
a23bc/op13-cve-2026-64560
language: C
murrez/CVE-2026-93399
Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointments; bookly_rollback_order cancels/deletes non-completed boo...
murrez/CVE-2026-89055
Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_submit with arbitrary Media Library attachment IDs in items[]....
murrez/CVE-2026-14281
Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields → admin. Python check/exploit PoC (PoCbit). | language: Python
InertFluid/cve-2026-61732-lab
Benign, self-contained reproduction of CVE-2026-61732 (Decepticon ChatML role-boundary forgery) | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Github推送中心
创建者: web5173
在简道云页面中绕过原生打印预览,直接通过 ZeroPrint 服务发送打印任务,实现无预览、无人工干预的静默打印。
Github推送中心
创建者: qwq-nm
NEXUS 网络安全态势感知平台 — 深色科技风落地页(GitHub Pages)
Github推送中心
创建者: liu-cmd463
网络安全系统学习
Github推送中心
创建者: KaiSky0823
Github推送中心
创建者: yuan293
本机运行的开源医院导诊原型:规则+本地 Qwen2.5 双模型、信息增益追问、急症安全闸门、FHIR 问题库与红队评测
Github推送中心
创建者: zkrana
Joomla security scanner for detecting malware, webshells, rogue admins, and exploit artifacts from SP Page Builder and JCE vulnerabilities.
Github推送中心
创建者: l1uz3
po0fw 防火墙白名单自动加白的 Magisk / KernelSU / APatch 模块:切网即时 + 定时兜底,root 绑定物理网卡直连,绕过代理 VPN
Github推送中心
创建者: invinciblenuonuo
本项目绕过了传统通用 OBD-II 标准协议采样率低(通常仅 1~2 个参数/秒)、PID 覆盖有限的弊端,直接通过 **EDIABAS 7.3 原生 API (`api32.dll`)** 与 **K+DCAN** 物理链路,与宝马发动机控制电脑(DME,如 MEVD17 家族)建立专有诊断通信。
Github推送中心
创建者: DeathShotXD
Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full ch...
Github推送中心
创建者: heterodoxin
Browser-based terminal: a real PTY on the server, an HTML/CSS terminal in the browser — only text and color cross the wire. Made with AI assistance.