Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The com
CVE-2026-32732;e21b852e448a11eeedefc9496d0bd901;Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS ex...
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a
CVE-2026-32729;9f86646d1045626bc170acbcd9169c4b;Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account l...
sirconscious/vulnerable_php_code
A deliberately insecure PHP web application used to test and benchmark AI-powered code security analysis tools. Contains: SQL Injection, XSS, RCE, Path Traversal, File Upload bypass, IDOR, hardcoded credentials, and debu...
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink receive
CVE-2026-32724;579735197416c21029858a5cc19f2b20;PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused...
h3raklez/CVE-2025-31722
CVE-2025-31722 — Jenkins Templating Engine RCE | language: Python
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import funct
CVE-2026-3227;93b665ea2cf36c62e0fdd7f9bf1c4479;A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS co...
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor
CVE-2026-32720;1f1ebce1c30ee5f85431996817e85124;The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to...
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/
CVE-2026-32719;13a875f83189578ec355b7f1188b9eed;AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.import...
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT
CVE-2026-32717;f4bc545869fdb5db9b79aa4b1a8175f5;AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, Anyth...
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, w
CVE-2026-32715;ab30f7c4c9ce2ebbf0744dda605a6257;AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-pr...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
fxa-2013/Poc_list
一个基于Python Flask开发的漏洞管理平台,支持导入Excel格式的漏洞扫描报告,智能关联资产信息,实现漏洞的可视化管理。 | stars: 5 | forks: 1 | updated 2026-07-30T01:13:12Z | pushed 2026-07-30T01:13:09Z
3886370410/tsbClEKOUV
该系统是一款面向安全开发流程的漏洞扫描器,用于自动识别软件中的安全漏洞。系统具备代码分析、漏洞匹配、风险评估等功能模块,采用深度学习技术,可高效识别和报告安全风险。支持多种编程语言和框架,辅助开发者提升软件安全性。 | stars: 1 | forks: 0 | updated 2026-03-03T15:31:22Z | pushed 2026-03-03T15:24:36Z
BarryCui/CuiEASM
攻击面管理+漏洞扫描+报告生成 | language: Python | stars: 3 | forks: 1 | updated 2026-03-04T01:12:02Z | pushed 2026-03-04T01:11:58Z
caibing3259/seckeeper
SecKeeper 是一款专为银河麒麟操作系统设计的安全检测工具,提供资产清点、合规检查、漏洞扫描和报告生成等一体化安全服务。 | language: Python | stars: 7 | forks: 2 | updated 2026-03-04T11:46:35Z | pushed 2026-03-02T14:22:38Z
huoqi1004/Xuanjian-Sec-Agent
玄鉴安全智能体是一个基于AI和MCP (Model Context Protocol) 架构的网络安全解决方案,通过集成多种主流安全工具和大语言模型,实现智能化的威胁检测、漏洞扫描、防御响应和取证分析。 ### 核心特性 - 🤖 **AI双模型架构** - 监督模型 (DeepSeek): 战略规划、结果审查、安全合规 - 执行模型 (本地Qwen/DeepSeek-Code/Claude等): 工具调用、实时响应 。 | langua...
5771323yang/vZIzDAuBRI
本系统是一款基于Python的漏洞扫描工具,采用Flask作为轻量级Web框架,MongoDB为数据库,整合OpenVAS和AWVS进行漏洞扫描。主要提供服务器资源监控、端口扫描、漏洞检测、Web漏洞扫描、域名解析及敏感目录查找等功能,旨在帮助企业或个人全面掌握网络安全状况,及时发现并处理安全隐患。 | stars: 1 | forks: 0 | updated 2026-03-05T21:01:59Z | pushed 2026-03...
5771323yang/nzNPckaUyV
本系统是一款基于Python的漏洞扫描工具,采用轻量级Web框架Flask和MongoDB数据库,集成了OpenVAS(GVM)病毒库。主要用途是监控服务器资源,执行端口扫描和漏洞检测,以及日志爬取和邮件告警。系统支持最新的Python 3,致力于发现并预警潜在安全风险,助力提升网络安全防护能力。 | stars: 1 | forks: 0 | updated 2026-03-05T21:13:20Z | pushed 2026-03-...
3886370410/eXDfwAOOpO
本系统是一款基于Python的web渗透测试工具,采用django框架构建功能模块,并通过MySQL管理数据。核心功能包括web漏洞扫描和端口安全检测,旨在帮助用户发现并解决网络安全问题,确保网络环境的安全稳定。系统简洁高效,为用户提供了一个可靠的安全检测平台。 | stars: 1 | forks: 0 | updated 2026-03-05T21:35:06Z | pushed 2026-03-05T21:35:03Z
3886370410/LbhgcaAYGU
本系统是一款基于Python的Web漏洞挖掘平台,采用Django框架和MySQL数据库构建。主要用途是对网站进行自动化漏洞扫描,核心功能包括SQL注入等漏洞扫描,以及漏洞报告生成,旨在帮助用户快速发现并解决网站安全漏洞,提升网络安全防护能力。 | stars: 1 | forks: 0 | updated 2026-03-06T00:29:01Z | pushed 2026-03-06T00:28:57Z
GreenHand0001/4952560187
该系统基于Python开发,用于网络安全资产扫描与管理。核心功能包括资产自动发现、漏洞扫描、风险评级、报告生成及结果可视化。技术特点采用模块化设计,支持多协议扫描,具备实时监测与历史数据追溯能力。系统可帮助用户全面掌握网络资产安全状况,提升安全管理效率。 | stars: 0 | forks: 0 | 2026-03-06T01:24:59Z