Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with mu
CVE-2026-24458;da84154b09231c2686de8bdcb88958b4;Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU...
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a manipulation of the argument Home can lead to s
CVE-2026-4237;5e5de09fbf90992b721442e65e282dbb;A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a ...
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve rem
CVE-2026-2462;924a21476eaa238ce8d850c6337d03b7;Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which al...
Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deleti
CVE-2026-2578;2acf2c6fbbc7635390e589ae1d28e9f7;Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read...
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fix
CVE-2025-69246;3671bc78842107c36b9dfd40be97ac39;Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throt...
Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated victim, results in arbitrary JavaScript execution in
CVE-2025-69245;cc6210d494928b5a7dd4589788240d8b;Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated vict...
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. Thi
CVE-2025-69243;fbca602b42ac237819802d3c10d0740b;Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enab...
Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim抯 browse
CVE-2025-69242;7b045f89d4b96fa6ec80b035444b5fae;Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbi...
manbahadurthapa1248/CVE-2025-66034-Poc-to-Get-RCE-for-HTB-VariaType
just a script. | language: Python
merlin-rce/Auto_car_ET2
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
anirudhabhowmik-ai/Scanner-Frontend
Web Application For Scan Document | language: HTML | stars: 0 | forks: 0 | updated 2026-03-15T21:28:54Z | pushed 2026-03-15T21:29:21Z | homepage: https://scanner-frontend-ten.vercel.app
oz10000/100-w-r-scanner-validado-ok
language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:29:02Z | pushed 2026-03-15T21:28:59Z
youhouz/patoune
Patoune - Super app animaux de compagnie (Scanner produits + Garde animaux + Messagerie) | language: JavaScript | stars: 0 | forks: 0 | updated 2026-03-15T21:29:43Z | pushed 2026-03-15T21:29:38Z | homepage: https://pepet...
diegovelasquezweb/a11y-scanner
language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-15T21:30:20Z | pushed 2026-03-15T21:30:16Z | homepage: https://a11y-scanner-tau.vercel.app
whisk3y3/WhisperGate
WhisperGate is a credential harvesting tool designed for professional penetration testers conducting authorized phishing and vishing engagements. It serves as a realistic endpoint compliance scanner that walks targets th...
Miika677/FruitScanner
AI-supplemented self-checkout fruit/vegetable weighing scale proof-of-concept. | language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:30:34Z | pushed 2026-03-15T21:30:30Z
hv6mn6bvqn-hue/dataflow-arbitrage-core
Automated data flow scanner for identifying price discrepancies across public sources | language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:30:35Z | pushed 2026-03-15T21:30:31Z
syeluru/iv-rank-scanner
language: Python | stars: 0 | forks: 0 | updated 2026-03-15T21:30:40Z | pushed 2026-03-15T21:30:37Z
Hrishabh1445/soc-analyst-portfolio
SOC Analyst portfolio with Microsoft Sentinel KQL detections, threat hunting queries, incident response playbooks, and security monitoring techniques. | stars: 0 | forks: 0 | updated 2026-03-13T06:30:06Z | pushed 2026-03...
VenkateshBolla/MitreThreatHunting
stars: 0 | forks: 0 | updated 2026-03-13T06:42:02Z | pushed 2026-03-13T06:41:59Z