Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
pawpic/CVE-2026-38526-POC
Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution | language: Python
pateldhyeyit/CVE-2026-37149
CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0.
0xBlackash/CVE-2026-20253
CVE-2026-20253 | language: Python
12hrformat/CVE-2026-35273-POC
language: Python
mirackayikci/CVE-2026-55584
CVE-2026-55584 — phpSysInfo IP Allowlist Bypass
0xBlackash/CVE-2026-47729
CVE-2026-47729 | language: Python
AmesianX/CVE-2026-53435
An offensive security researcher + an AI vs. a fresh n-day: building the first public PoC for CVE-2026-53435 in one Friday night. Raw 8h20m log inside. | language: Python
v4ltonn/CVE-2026-42530
Scanner PoC for CVE-2026-42530 -- nginx 1.31.0-1.31.1 HTTP/3 QPACK encoder stream Use-After-Free (CVSS 9.2) | language: Python
joshuavanderpoll/CVE-2026-49772
CVE-2026-49772 — The Events Calendar (WordPress) unauthenticated blind SQLi PoC | topics: blind-sql-injection, cve, cve-2026-49772, exploit, poc, proof-of-concept, sql-injection, sqli, the-events-calendar, wordpress, wor...
joshuavanderpoll/CVE-2026-54806
Unauthenticated PHP Object Injection to RCE in WP Activity Log <= 5.6.3.1 (CVE-2026-54806) | topics: cve, cve-2026-54806, deserialization, exploit, php-object-injection, poc, proof-of-concept, rce, remote-code-execution,...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Sharan-Ravindran/python-security-tools
Python security tools built from scratch while learning ethical hacking — port scanner, web vulnerability scanner, and password analyser. | language: Python | stars: 1 | forks: 0 | updated 2026-03-19T07:06:51Z | pushed 2...
nikodacat/AI-security-agant
an AI with all the basic security tools and standards to improve security, working for both home-use computer and enterprise security planning | stars: 0 | forks: 0 | updated 2026-03-19T07:27:59Z | pushed 2026-03-19T07:2...
Sivajith0803/angel-garden-safety-app
A full-stack women's safety web application designed to provide real-time security tools, emergency alerts, and community support. Built with a focus on rapid response and user-centric design. | language: JavaScript | st...
Zoe-life/Bubbble
A security tool that wraps around any link sent, determines the legitimacy of the link and prevents security attacks via these links by creating a 'bubble' around it and enabling you to safely visit any link | language: ...
volodymyrshk/mcpaudit
An open-source security tool for discovering and auditing Model Context Protocol (MCP) servers in AI workflows | language: TypeScript | stars: 3 | forks: 0 | updated 2026-03-19T17:18:02Z | pushed 2026-03-19T08:08:49Z
xransum/valkyrie-tools
A security tools suite built for humans. | topics: cli, command-line, information-gathering, network-analysis, python, security, security-tools | language: Python | stars: 0 | forks: 0 | updated 2026-03-19T01:47:43Z | pu...
ctokx/aidos
Autonomous LLM-powered DoS resilience assessment framework that orchestrates open-source security tooling for recon, analysis, stress testing, and reporting. | language: Python | stars: 0 | forks: 0 | updated 2026-03-18T...
thecosmicexplorer/tools
Daily CVE scanners and offensive security tools for bug bounty & red team — one new tool pushed every day | topics: bug-bounty, cve, penetration-testing, python, red-team, security | language: Python | stars: 0 | forks: ...
MariaMancuso05/Semantic-Password-Analyzer
AI-powered password security tool that analyzes semantic predictability instead of simple regex patterns. It detects obfuscated common words and explains why your password isn't as clever as you think. | language: CSS | ...
sec0ps/va-pt
The VAPT Toolkit provides a streamlined way to install, configure, and maintain a complete penetration testing environment with 50+ security tools and custom automation frameworks organized across multiple categories. | ...