Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code executi
CVE-2025-54920;8f8f859801130729cb710d0ed0cb5da7;This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3...
jagadishvajjha94-pixel/Rce-conference
language: HTML | homepage: https://raceconference.vercel.app
osamaloay/navigate-cms-rce
metasploit RCE code for navigate cms portal for php written in python | language: Python
Skynoxk/CVE-2026-27944
Automated exploit script for CVE-2026-27944 (Nginx UI). Downloads/decrypts backups, extracts system secrets, and creates rogue admin accounts for full dashboard access. | language: Python
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, an
CVE-2026-1948;50d4e3dfe52fcb28e65fc7878d982a08;The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactiva...
Version 1.6.1 of the Flash Payments package graphql-upload-minimal is vulnerable to prototype pollution. This vulnerability, located in the processRequest() function, allows an attacker to inject special property names i
CVE-2025-65587;a1cfbab742f640d3c0d253218b3593a8;Version 1.6.1 of the Flash Payments package graphql-upload-minimal is vulnerable to prototype pollution. This vulnerability, located in the processRequest() function, allow...
Skynoxk/CVE-2026-27944-POC
language: Python
danaug23/detect_CVE-2026-25177
Production-safe scanner that detects CVE-2026-25177 (AD SPN Unicode Collision) exploitation on Active Directory Domain Controllers. Read-only. | language: Python
Chromium: CVE-2026-3910 Inappropriate implementation in V8
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2021">Google Chrome Releases</a> for mo...
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-0385;beaa6c5c1ad6e34de6adb3cddb0d60f0
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
5771323yang/hzRtumCRLx
本系统是一套基于Shiro框架的渗透测试研究项目,包括论文和前后端程序源代码。系统旨在提供渗透测试环境,支持安全漏洞检测与分析。功能模块涵盖安全漏洞扫描、风险评估、漏洞报告生成等。采用Shiro框架,实现权限控制和身份验证,保障系统安全稳定运行。 | stars: 1 | forks: 0 | updated 2026-02-05T15:13:29Z | pushed 2026-02-05T15:10:58Z
5771323yang/DyIJXmkveh
该系统是一款面向安全开发流程的漏洞扫描器,用于自动识别软件中的安全漏洞。系统具备代码分析、漏洞匹配、风险评估等功能模块,采用深度学习技术,可高效识别和报告安全风险。支持多种编程语言和框架,辅助开发者提升软件安全性。 | stars: 1 | forks: 0 | updated 2026-02-06T06:06:00Z | pushed 2026-02-06T06:05:57Z
kevin5771323/agTrCtd4Cx
该系统基于Python开发,用于网络安全资产扫描与管理。核心功能包括资产自动发现、漏洞扫描、风险评级、报告生成及结果可视化。技术特点采用模块化设计,支持多协议扫描,具备实时监测与历史数据追溯能力。系统可帮助用户全面掌握网络资产安全状况,提升安全管理效率。 | stars: 1 | forks: 0 | updated 2026-02-06T23:14:42Z | pushed 2026-02-06T23:14:27Z
3886370410/kJOxAswDTT
该系统基于Python开发,用于网络安全资产扫描与管理。核心功能包括资产自动发现、漏洞扫描、风险评级、报告生成及结果可视化。技术特点采用模块化设计,支持多协议扫描,具备实时监测与历史数据追溯能力。系统可帮助用户全面掌握网络资产安全状况,提升安全管理效率。 | stars: 1 | forks: 0 | updated 2026-02-07T15:42:35Z | pushed 2026-02-07T15:42:32Z
J09715/Vulnerability-Scanning-tool
Python全量漏洞扫描工具,支持端口/WEB/子域名/DNS扫描,生成多格式报告 | language: Python | stars: 1 | forks: 2 | updated 2026-06-05T14:12:00Z | pushed 2026-06-05T14:11:44Z
xiaom0919/Vulnerability-scanning
一个基于 FastAPI 的 Web 漏洞扫描工具,集成 Wapiti3、SQLMap、XSStrike 等多种安全扫描器,提供 RESTful API 接口。 | language: Python | stars: 3 | forks: 0 | updated 2026-03-15T14:13:39Z | pushed 2026-02-03T14:53:30Z
yuyouquan/vuln-scan-dashboard
漏洞扫描实时监控看板 | language: Python | stars: 0 | forks: 0 | updated 2026-02-22T03:55:12Z | pushed 2026-02-22T03:55:09Z
onewinner/Xnexus
Xnexus 星枢:面向未来的全栈一体化网络安全平台。集资产测绘、漏洞扫描、渗透测试、威胁情报与自动化编排于一体,旨在为安全团队提供从发现到响应的闭环解决方案。汇万象如星罗,定乾坤于枢机;在数字洪流里,铸就洞察先机的安全防线。 | stars: 0 | forks: 0 | updated 2026-02-25T08:03:37Z | pushed 2026-02-25T08:03:34Z
imkerbos/mxsec-platform
矩阵云安全平台(MXSec Platform)是一套集成 EDR、CWPP、基线安全、文件完整性监控(FIM)、漏洞扫描、应用安全于一体的新一代云原生安全中台。 | language: Go | stars: 9 | forks: 2 | updated 2026-03-16T06:17:05Z | pushed 2026-02-23T17:25:13Z
laowang111101/izQcDIAOuV
该系统基于Python开发,用于网络安全资产扫描与管理。核心功能包括资产自动发现、漏洞扫描、风险评级、报告生成及结果可视化。技术特点采用模块化设计,支持多协议扫描,具备实时监测与历史数据追溯能力。系统可帮助用户全面掌握网络资产安全状况,提升安全管理效率。 | stars: 0 | forks: 0 | updated 2026-03-02T11:00:49Z | pushed 2026-03-02T11:00:38Z