Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Xmyronn/CVE-2026-10170-RCE
rfxn/cpanel-sessionscribe
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSe...
Jenderal92/CVE-2026-8181
CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only. | topics: authentication-bypass, burst-statistics, cve, cve-2026-8181, exploit, pentesting, python2, res...
Jenderal92/CVE-2026-5118
CVE-2026-5118 – Python2 mass exploit for Divi WordPress plugin Unauthenticated administrator registration via admin-ajax.php. Multi‑threaded scanner with nonce extraction. | topics: cve-2026-5118, exploit, mass-exploit, ...
Jenderal92/CVE-2026-4885
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload | topics: cve-2026-4885, exploit, pentesting, python, vulnerability, wordpress | language: Python
letsr00t/CVE-2026-43494-PinTheft-PoC
language: C
hadhub/CVE-2026-49345-Mercator-SSRF
SSRF Discovered in Mercator | language: Python
hadhub/CVE-2026-49344-Mercator-JSON-DSL
language: Python
HORKimhab/CVE-2026-39987
CVE-2026-39987 - Draft
microwaveabi/pharmacy-sqli-CVE-2026-7392
SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection | language: JavaScript
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
JE2Se/SecTools
优雅的命令行安全工具集成平台,可将命令行工具优雅的添加GUI界面,赋予图形化操作,配置优雅简单,把常用的命令配置保存,一键执行,终于不用因太久没用忘了而导致在小伙伴面前尬住了,支持跨平台。 | stars: 1 | forks: 0 | updated 2026-01-06T08:41:34Z | pushed 2025-12-30T06:02:57Z
ADA-XiaoYao/Web-Pentest-Expert-Toolbox
这是一个包含**113个精选Web渗透测试工具**的交互式CLI应用。旨在帮助渗透测试专家快速查找、了解和使用各类安全工具。 | language: Python | stars: 5 | forks: 0 | updated 2026-03-18T22:10:28Z | pushed 2026-01-08T04:42:20Z
StudyJailbro/APIFinder
#APIFinder# 一键快速扫描、自动识别,可以精准捕捉网页中暴露的各类 API 接口的安全工具 | language: Python | stars: 5 | forks: 0 | updated 2026-01-10T18:46:49Z | pushed 2025-08-17T16:05:25Z
Tobin-wu/aliveGuard
活着么?是一款专为独居人群设计的安全工具,通过每日签到机制,当用户连续多日未签到时,系统会自动发送短信/邮件/语音通知紧急联系人,确保用户的安全。 | language: Java | stars: 0 | forks: 0 | updated 2026-01-16T03:05:22Z | pushed 2026-01-16T03:05:18Z
MARKJY-China/st-nexus
由MARKJY独立开发的一款基于 Golang 开发的高性能全面网络安全工具基础框架系统-“泇影枢纽”。旨在为网络管理员、安全研究人员和白帽黑客提供一套轻量级、模块化的全面解决方案 | language: Go | stars: 0 | forks: 0 | updated 2026-01-18T08:31:09Z | pushed 2026-01-18T08:28:39Z
stpaloma/0g-sentinel
0G Sentinel 是一个基于 0G Compute Network 构建的去中心化 AI 安全扫描器。 它不依赖传统中心化 API,而是直接通过链上协议调用分布在全球的高性能推理节点。用户只需在“极客终端”界面输入钱包地址,系统即可自动通过 0G 网络进行寻址、加密请求和支付。 AI 节点(如 DeepSeek/Llama)会对目标地址进行实时风险评估,最终生成一份包含风险评分和详细分析的安全报告。这不仅是一个安全工具,更是 We...
iSee857/ReverseIP-CN
ReverseIP-CN 是一款专为中文网络环境优化的IP反查域名工具,能够快速查询指定IP/域名关联的所有网站,增加输入清洗优化查询速率。`ReverseIP` `IP反查` `网络安全工具` `红队工具` `资产测绘` `中文网络` `国内API` `企业安全` `威胁情报` `域名解析` | language: Python | stars: 20 | forks: 0 | updated 2026-02-02T13:34:25Z...
si1ence90/SecAgentCore
SecAgentCore是基于 ReAct (Reasoning + Acting) 循环的网络安全智能体系统。它能够理解自然语言描述的安全任务,自动规划执行步骤,调用相应的安全工具,并生成结构化的分析报告。 | language: Python | stars: 6 | forks: 0 | updated 2026-02-03T06:03:49Z | pushed 2026-01-06T07:06:16Z
Xuuuuu04/commons-lang4cj
Apache Commons Lang3 的仓颉移植库,提供类型安全工具能力。 | topics: apache-commons, cangjie, lang3, library, toolkit, utilities | language: Cangjie | stars: 1 | forks: 0 | updated 2026-02-07T05:25:17Z | pushed 2026-02-07T05:25:14Z | homep...
968626/ARP-Spoofing-Detection-and-Defense-System
ARP欺骗检测与防御系统是一个功能完整的网络安全工具,专门用于检测和防御ARP欺骗攻击。系统采用模块化设计,包含检测、防御、取证、机器学习等多个功能模块。信息安全网络安全毕业设计 | stars: 0 | forks: 0 | updated 2026-02-09T01:14:23Z | pushed 2026-02-09T01:14:19Z