Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
codeb0ssx/-Ultimate-CVE-2026-61511
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execut...
extratao/CVE-2026-51302-PoC
Clickbait. The CVE is AI slop.
theopaid/CVE-2026-66749-Unchecked-Room-Lookup-Leads-to-Server-Crash-Let-s-Chat
Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)
theopaid/CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
theopaid/CVE-2026-66751-Insufficient-Access-Controls-Allow-for-Unauthorized-Room-Deletion-Let-s-Chat
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
theopaid/CVE-2026-67183-Unauthenticated-Memory-Leak-Leads-To-Memory-Exhaustion-TinyWeb
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
theopaid/CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb
Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)
theopaid/CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb
Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)
theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
RainmeoX/Web-Security-Learning
网络安全学习项目 | Web 安全知识整理与实践 | 渗透测试、漏洞分析、安全防护 | topics: cybersecurity, learning, penetration-testing, security, web-security | language: Python | stars: 1 | forks: 0 | updated 2026-07-23T02:36:02Z | pushed 2026-07-23T02:35:5...
0zbq/PenetrationTesting_StudyNotes
这是一个用于存放我学习渗透测试时笔记的仓库 | stars: 0 | forks: 0 | updated 2026-07-23T03:53:19Z | pushed 2026-07-23T02:07:10Z
keecth/FakeCryptoJS
CryptoJS常规加解密自吐密钥、加解密方式,快速定位加解密位置(无视混淆)。SRC和常规渗透神器 | language: Python | stars: 624 | forks: 77 | updated 2026-07-23T07:02:37Z | pushed 2026-07-20T10:28:15Z
Aumddd/PentestReportGenerator
Pentest Report Generator 是一个全栈自动化渗透测试报告生成系统。 | language: Python | stars: 0 | forks: 0 | updated 2026-07-23T10:07:35Z | pushed 2026-07-23T10:07:31Z
shyrel666/RustForge
面向初学者的 AI 引导式 Web 渗透测试学习桌面应用:MITM 抓包代理 + AI 漏洞分析 + 渗透任务树 + OWASP/CWE 知识库。 | topics: ai-agents, pentesting, rust, security, security-tools, vulnerability-analysis, web-security | language: Rust | stars: 0 | forks: 0 | upd...
an7ln/wmpf-mcp-bridge
ai渗透测试小程序 | language: TypeScript | stars: 101 | forks: 14 | updated 2026-07-24T01:37:03Z | pushed 2026-07-18T09:55:13Z
CuriousLearnerDev/Online_Tools-AI
一个面向 Web 版桌面 安全测试的 AI Agent 平台,集成侦察、分析、规划、工具调用与反馈学习,实现自主完成渗透测试工作流An AI Agent platform for web-based security testing, integrating reconnaissance, analysis, planning, tool orchestration, and feedback-driven learning to au...
yuanweipeifang/AgentSec-RedTeam-Lab
研究智能体红队技术与生态治理,自建红队智能体进行安全渗透 | language: Python | stars: 0 | forks: 0 | updated 2026-08-06T02:23:41Z | pushed 2026-08-06T02:23:32Z
lingxiasanshi/web-audit
用于web渗透的小skill | language: Python | stars: 2 | forks: 0 | updated 2026-07-24T09:46:47Z | pushed 2026-07-23T08:55:37Z
yzdily/xuanjian
一个会操作浏览器、会抓包改包、会按照方法论执行、会自己验证漏洞的自动化渗透测试 Agent | language: Python | stars: 6 | forks: 0 | updated 2026-08-07T10:06:29Z | pushed 2026-08-07T10:04:55Z