Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
soralis0912/CVE-2026-43499-pmg110-root
language: C
soralis0912/CVE-2026-43499-warhol-root
language: C
5kr1pt/glpi-logbleed
PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter | topics: cve-2026-53629, glpi, poc, security, sql-injection, vulnerability-research | language: Python | homepage: https://medium.com/@5kr1pt/re...
riddhimaan-sth404/CVE-2026-57973
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-le...
zer0dayf/CVE-2026-65008
CVE-2026-65008 | language: Python
javokhir-sec/CVE-PoC-Hub
🛡️ CVE Proof-of-Concept Hub — 21 security advisories · 80+ vulnerabilities · 19 CVEs under review · 1 PUBLISHED (CVE-2026-66412) | topics: bug-bounty, cve, exploit, poc, proof-of-concept, security, vulnerability | langua...
marcgoam/CVE-2026-54121-CertiGhost
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse. | language: Python
ChPratik/CVE-2026-9830
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowin...
marcgoam/CVE-2026-54121-CertiGhost
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse. | language: Python
dinosn/fastjson-jsontype-rce-lab
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymor...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
jahnfrens/qJIPKWSBEZ
【Java计算机毕业设计分享】基于Shiro框架的渗透测试管理系统,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-07-11T15:56:51Z | pushed 2026-07-11T15:56:45Z
jahnfrens/XzkizooXxj
【Java计算机毕业设计分享】基于Jboss的渗透测试研究平台,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-07-11T16:08:23Z | pushed 2026-07-11T16:08:17Z
jingqing11/ai-pentest-assistant
AI-Powered Web Penetration Assistant | AI 驱动的 Web 渗透测试辅助工具 | language: Python | stars: 0 | forks: 0 | updated 2026-07-11T18:47:15Z | pushed 2026-07-11T18:47:10Z
soevai/MetaSword
二次元风格逆向渗透集成工具箱,内置AI Agent,面向安全研究与技术学习 | language: JavaScript | stars: 345 | forks: 28 | updated 2026-07-12T03:50:00Z | pushed 2026-07-09T10:46:09Z | homepage: https://www.52tt.pro/tools/sword/
Kavlina/Kali_DVWA
一个记录我学习DVWA靶场渗透测试的仓库 | stars: 0 | forks: 0 | updated 2026-07-12T04:17:09Z | pushed 2026-07-12T04:17:03Z
ctkqiang/CVE-Exploits
一个收集各种CVE漏洞的PoC(概念验证)或Exploit(漏洞利用)工具的仓库。旨在为安全研究、渗透测试提供参考和便利。 | language: Go | stars: 5 | forks: 1 | updated 2026-07-28T06:44:37Z | pushed 2026-07-29T14:11:04Z
buzhimingdeaikun/-Python
通过字典枚举方式对目标站点进行目录遍历,支持状态码识别与超时控制,用于渗透测试前期信息收集阶段 | language: Python | stars: 0 | forks: 0 | updated 2026-07-12T12:57:13Z | pushed 2026-07-12T12:56:57Z
zzzyxyfj/pentest_ALL
个人渗透测试知识库 | stars: 2 | forks: 0 | updated 2026-08-07T10:09:15Z | pushed 2026-08-07T10:08:06Z
doubao432/bio-b1-c04-osmosis-v010
高中生物渗透作用 2D 交互模拟器 v0.1.0 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-07-12T22:02:35Z | pushed 2026-07-12T22:02:30Z
str3ct/HeaderBypass
HeaderBypass — Manifest V3 Chrome 扩展:批量新增/修改/删除 HTTP 请求头与响应头。原生 JS 免构建,基于 declarativeNetRequest 动态规则,内置 52 项安全测试预设(渗透/漏洞挖掘/金融对抗分类)。 | language: JavaScript | stars: 1 | forks: 1 | updated 2026-07-13T08:06:57Z | pushed 202...