Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
doany1/CVE-2026-24849
Proof-of-concept exploit for CVE-2026-24849, an authenticated path-traversal / arbitrary file read in OpenEMR's Fax/SMS (EtherFax) module. Any authenticated user regardless of privilege level can read arbitrary files fro...
hnytgl/CVE-2026-42945
这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。 | language: Python
hnytgl/CVE-2026-34197
这是一个面向防守和内网排查的 Apache ActiveMQ Classic 暴露面检测工具,用于辅助评估 CVE-2026-34197 相关风险。 | language: Python
oryk0/CVE-2026-23744
CVE-2026-23744 Reverse shell | language: Python
HORKimhab/CVE-2026-20245
CVE-2026-20245 - Cisco SD-WAN - Draft
INTELEON404/CVE-2026-49009
Mender Server - Authenticated Path Traversal to RCE | topics: cve, cve-2026-49009, cve-search, cves, mender, nuclei-templates, pathtraversal, rce, remote-code-execution, to
frudotz/ISU-SecOps-Nginx-RCE
Nginx Downgrade & RCE CVE-2026-0211 | topics: buffer-overflow, cve-2026-0211, http, nginx, quic, rce | language: Python
partywavesec/CVE-2026-25860
CVE-2026-25860 POC git
yurahshell/CVE-2026-41940
language: Python
josephfelix/CVE-2026-42945-nginx-rift
Repository for studying the CVE-2026-42945 vulnerability in nginx < 1.30 | language: Jupyter Notebook
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
sign9981/s1Hua
s1Hua(丝滑)轻量级|易拓展|资产收集工具-一条命令,无人值守(适用src|红队外网资产收集|低配置VPS丝滑运行)子域名发现|指纹识别|DNS解析|端口扫描|目录发现等 | language: Python | stars: 3 | forks: 0 | updated 2026-01-23T01:42:34Z | pushed 2025-11-28T08:20:17Z
di-ao/jiuji
一个小轱辘,调用常用工具帮助红队快速自动化打点。 | language: Python | stars: 31 | forks: 5 | updated 2026-01-25T10:06:14Z | pushed 2026-01-25T10:06:11Z
GodYounger/olight
红队信息收集打点系统 - Domain identification, asset discovery, and vulnerability scanning | language: Java | stars: 0 | forks: 0 | updated 2026-01-26T04:40:30Z | pushed 2026-01-26T04:40:26Z
s7safe/Rad-Team-tools
赏金技巧|红队|RedTeam|信息侦查|漏洞挖掘 | topics: bugbounty, bugbountytips, hackerone, redteam | stars: 129 | forks: 15 | updated 2026-03-20T01:15:04Z | pushed 2025-10-17T01:14:09Z
kk12-30/WuJian
无剑红队作战平台-漏洞扫描平台 | stars: 3 | forks: 0 | updated 2026-01-28T05:04:17Z | pushed 2025-11-03T07:20:03Z
qqliushiyu/Red-Team-Knowledge
红队知识库 | stars: 2 | forks: 1 | updated 2026-01-30T01:30:40Z | pushed 2025-12-03T04:52:06Z
ChinaRan0/Red_Team_Collaboration
一款用于红队攻防演练协作、渗透测试漏洞生命周期管理平台 | language: HTML | stars: 34 | forks: 4 | updated 2026-02-02T09:52:21Z | pushed 2025-11-24T03:36:53Z
25smoking/PhantomHarvest
PhantomHarvest 是一个隐蔽的后渗透传输软件,专为红队评估和安全研究设计。它能够从目标系统中提取敏感信息,并支持隐蔽的本地保存或远程传输。 | language: C# | stars: 9 | forks: 3 | updated 2026-03-19T06:33:38Z | pushed 2025-11-27T16:23:15Z
wr0x00/Lsploit
Lsploit is a comprehensive asset collection and vulnerability scanning tool. Lsploit是一款便携式综合资产分析及漏扫框架,拥有高性能,功能丰富,结合最新漏洞通告,嵌入ai,可自行组装exp,poc,方便红队快速打点 | topics: cve, hack-framework, hacking-tool, hackingframework, python, ...
ruisika/jsapiscan
红队快速扫描js文件检查工具 | stars: 78 | forks: 6 | updated 2026-08-16T04:07:32Z | pushed 2026-07-09T06:21:37Z