Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
theopaid/CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille
Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)
theopaid/CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field
Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field | language: Python
sfewer-r7/CVE-2026-16232
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token. | language: Python
darses/CVE-2026-50522
Microsoft SharePoint CVE-2026-50522 | language: ASP.NET
ivmks74/IIITA-IoT-Security-Research
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
tc4dy/CVE-2026-53921-PoC-Exploit
CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) 🛡️ Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (IA_NA/IA_PD) overflow with MIPS/ARM shellcode, ROP chains, S...
mumaosong/CVE-2026-43499-xiaomi_8e-GUI
CVE-2026-43499-xiaomi_8e密钥离线计算客服端,网页端:miauth.mu667.ccwu.cc | language: Python
Chromium: CVE-2026-15132 Uninitialized Use in V8
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15115 Insufficient validation of untrusted input in WebAppInstalls
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15113 Use after free in Autofill
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
caichao061025-lang/Quench
淬火 (Quench) - 轻量级 Webshell 管理工具,专为授权渗透测试、CTF 竞赛和安全教学而设计 | language: Python | stars: 5 | forks: 0 | updated 2026-07-20T07:37:29Z | pushed 2026-07-17T16:12:48Z
ClumsyChou/Kali
使用Kali Linux进行渗透测试基础训练 | stars: 0 | forks: 0 | updated 2026-07-20T08:15:26Z | pushed 2026-07-20T08:14:53Z
crabin/AutoPentest-XL
AutoPentest-XL 是一个基于 LangGraph 多 Agent 编排的自主渗透测试平台,通过增强型 RAG 和严格安全围栏实现从初始侦察到 Root 提权的全流程自动化。 | language: Python | stars: 4 | forks: 1 | updated 2026-07-21T07:29:10Z | pushed 2026-07-21T07:28:41Z
a5155613/Termux-SecBox
安卓离线安全渗透工具箱 | language: Python | stars: 2 | forks: 0 | updated 2026-07-21T13:40:50Z | pushed 2026-07-18T17:24:49Z
CharlieYin05/Flask_TravelBlog_v2.0
本项目脱胎于cits3403-project。本项目用于TravelBlog的维护与渗透测试 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-07-19T04:42:20Z | pushed 2026-07-21T15:42:38Z | homepage: https://travelblog.cy-server.com
Maple0208/Paradox
Paradox是一个面向Web渗透与代码审计的企业管理系统靶场,重点训练逻辑漏洞,同时包含注入、XSS、文件上传等常见漏洞场景。 | language: HTML | stars: 24 | forks: 0 | updated 2026-07-22T06:04:13Z | pushed 2026-07-21T14:43:57Z
nmcp0114/Aipentest-burp
burpsuite的AI渗透插件demo | language: Java | stars: 0 | forks: 0 | updated 2026-07-27T00:47:21Z | pushed 2026-07-27T00:47:18Z
WAjkl/pentest-gui
16 个渗透测试工具的集成 GUI 平台,一键安装,开箱即用 | topics: chinese, nuclei, pentest, python, security-tools, thinker, vulnerability-scanner | language: Python | stars: 1 | forks: 0 | updated 2026-07-22T09:54:15Z | pushed 2026-07-17T19:38:...
Alyssa-syx/ai-autonomous-lab-hydrogen-demo
一个基于 AI 自主闭环控制的 DS 双电解池氢渗透实验演示项目 | stars: 0 | forks: 0 | updated 2026-07-22T16:20:05Z | pushed 2026-07-22T16:17:50Z
RainmeoX/Web-Security-Learning
网络安全学习项目 | Web 安全知识整理与实践 | 渗透测试、漏洞分析、安全防护 | topics: cybersecurity, learning, penetration-testing, security, web-security | language: Python | stars: 1 | forks: 0 | updated 2026-07-23T02:36:02Z | pushed 2026-07-23T02:35:5...