Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
theopaid/CVE-2026-66751-Insufficient-Access-Controls-Allow-for-Unauthorized-Room-Deletion-Let-s-Chat
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
theopaid/CVE-2026-67183-Unauthenticated-Memory-Leak-Leads-To-Memory-Exhaustion-TinyWeb
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
theopaid/CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb
Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)
theopaid/CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb
Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)
theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
theopaid/CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
theopaid/CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille
Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Pallas Bot 4.0 官方扩展:MAA 远控
创建者: PallasBot
Pallas Bot 4.0 官方扩展:MAA 远控
窗帘行业每日情报 Skill:行业知识、报告、热点、竞品、供应链与招投标信息收集,自动生成中文 PDF。
创建者: wl13643464077-dev
窗帘行业每日情报 Skill:行业知识、报告、热点、竞品、供应链与招投标信息收集,自动生成中文 PDF。
安全漏洞审计报告集 | Security Vulnerability Assessment Reports
创建者: hackliu
安全漏洞审计报告集 | Security Vulnerability Assessment Reports
MintKangaroo/Cyber-Offensive-and-Defensive-Exercise
공방(攻防) 통합 사이버 레인지 — 11개 ICS/OT 섹터 디지털 트윈, EDR/SIEM, 69 CTF 챌린지, 다중 팀 대회 운영(Range/Match 격리·초기화·안전통제) | topics: blue-team, ctf, cyber-range, ics-security, mitre-attack, ot-security, purple-team, red-team, security-training...
zzzjiushi/web_scanner
一个轻量级模块化 Web 漏洞扫描器(DAST),实现了 SQL 注入,XSS,命令注入等诸多漏洞的 自动化检测,具备可扩展的插件化架构。 | language: Python | stars: 0 | forks: 0 | updated 2026-07-16T09:57:57Z | pushed 2026-07-16T09:57:45Z
gshhwht/python-security-scanner
基于python开发的漏洞扫描小工具 | language: Python | stars: 1 | forks: 0 | updated 2026-07-19T05:10:46Z | pushed 2026-07-19T05:01:59Z
gutddts/SentinelScan
🔍 全栈漏洞扫描管理平台 — React + FastAPI,支持端口扫描/HTTP头检测/SSL验证/漏洞检测,可视化仪表盘与PDF报告 | language: TypeScript | stars: 1 | forks: 0 | updated 2026-07-21T10:20:16Z | pushed 2026-07-21T09:55:22Z
xiabai2008/rayscan
RayScan v2.0 — 全栈 Web 漏洞扫描器。8种SQLi + 6种XSS + 12种OA + 多引擎聚合(Nuclei/AWVS/Nessus/MSF) | topics: bug-bounty, nuclei, penetration-testing, pentest, red-team, security, sql-injection, vulnerability-scanner, web-security, xss |...
testnet0/testnet
TestNet资产管理系统(资产管理|信息收集|暴露面管理|子域名扫描|C段扫描|端口扫描|漏洞扫描|Hunter|Fofa) | language: PLpgSQL | stars: 754 | forks: 84 | updated 2026-08-10T12:25:18Z | pushed 2026-08-10T12:24:19Z
aicodow/LLM-Kitty
基于Promptfoo重构的Python版开源大语言模型(LLM)红队对抗性评估框架。 | language: Python | stars: 1 | forks: 0 | updated 2026-07-17T14:19:42Z | pushed 2026-07-15T18:29:05Z