Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This is
CVE-2026-3888;05e9e6128913244256f83fe3b90c27e5;Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to...
ThanniKudam/codex-notify-rce-poc
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. Wh
CVE-2025-62320;5d44d34d32e5e0efb070739e7a743500;HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker...
p0dalirius/CVE-2020-14144-GiTea-git-hooks-rce
A script to exploit CVE-2020-14144 - GiTea authenticated Remote Code Execution using git hooks | topics: cve-2020-14144, git, gitea, hook, rce | language: Python | homepage: https://podalirius.net/en/articles/exploiting-...
HCL Sametime is vulnerable to broken server-side validation. While the application performs...
CVE-2025-31966;7bfc69069a1ecef6d3725c15183c5874
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a...
CVE-2026-4271;9bcc80b93388e4a8e86b2fef7f90d392
Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version meta
CVE-2026-26929;cec02fc8ef4435c5a64303e9989d10d2;Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (w...
Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission
CVE-2026-28563;4be0d11524f2fd77526f7212c1fb6c5a;Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenti...
Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same dom
CVE-2026-28779;fdca579da20883c806544a3c17615fae;Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This all...
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workf
CVE-2026-30911;189b156ab1c19903afc5dd296f757e6c;Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
ypratap11/ema-scanner
EMA Scanner for Stocks and Crypto | language: HTML | stars: 0 | forks: 0 | updated 2026-03-15T21:16:00Z | pushed 2026-03-15T21:15:57Z
LalithSakinala/python-port-scanner
language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:16:14Z | pushed 2026-03-15T21:16:11Z
Saif8671/vulnerability-scanner
language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:17:57Z | pushed 2026-03-15T21:17:54Z | homepage: https://vulnerability-scanner-kohl.vercel.app
nxtg-ai/faultline-pro
FM-agnostic AI Trust & Safety scanner — multi-provider claim verification (868 tests) | language: TypeScript | stars: 1 | forks: 0 | updated 2026-03-15T21:18:25Z | pushed 2026-03-15T21:18:22Z
Yuyuyumi8/EventLog-Scanner
A C# tool that analyzes the 4624 and 4625 login entries in the Windows Security Event Log. A tool that quickly extracts the remote IP, username, and time information. | topics: cybersecurity, digital-forensics, event-log...
Jenak5/ev_scanner
Scans odds and finds probabilities | language: HTML | stars: 0 | forks: 0 | updated 2026-03-15T21:19:19Z | pushed 2026-03-15T21:19:16Z
Teycir/ApiHunter
An async, modular web security scanner written in Rust. Great for quickly baselining API exposure in staging or production-like environments, and for catching regressions after gateway, WAF, or auth changes. Innovation: ...
sudolifeagain/ajmun-x
MUN conference attendance management: Discord OAuth login, QR code distribution via Bot DM, staff scanner, Google Sheets sync | language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-15T21:19:45Z | pushed 2026-03-1...
Bert-Sec/UsernameScanner
Bert-Sec/UserScanner | language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:20:05Z | pushed 2026-03-15T21:20:02Z
aspirepp-lab/scanner-crypto-eth-btc
language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:20:18Z | pushed 2026-03-15T21:20:14Z