Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Chromium: CVE-2026-16413 Out of bounds write in ANGLE
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
BiiTts/POC-CVE-2026-65971
Proof-of-concept and technical write-up for CVE-2026-65971 — SQL injection via the sortDirection Livewire property in power-components/livewire-powergrid (< 6.10.4) | topics: cve, cve-2026-65971, laravel, livewire, poc, ...
nullRoot-Red/CVE-2026-23744
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+). | language: Python
raphy76/wp2shell-poc-fulljs
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches) | language: JavaScript
karollooool/CVE-2026-50416-writeup-and-poc
CVE-2026-50416: Windows 11 KASLR bypass | topics: cve, cve-2026-50416, information-disclosure, kaslr, kaslr-bypass, kernel, leak, msrc, poc, proof-of-concept, vulnerability, win32k, windows, windows-11, writeup, writeups...
abhinavagarwal07/abhinavagarwal07.github.io
RingWraith: CVE-2026-33150 and CVE-2026-33179 — Use-After-Free and NULL Dereference in libfuse io_uring | language: C
CerberusMrXi/Flowise-CVE-2026-58057-exploit
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file up...
ghapvharmo/gha-lab-a815a82f03-1
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
ghapvharmo/gha-lab-a5c1876997-1
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
4minx/CVE-2026-14266
CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
brentberli/JukgRZxEhs
【Python计算机毕业设计分享】基于Python的web渗透漏洞扫描工具研究与应用,MySQL Python开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-07-11T15:04:26Z | pushed 2026-07-11T15:04:19Z
2681244490-droid/vulscan-platform
企业级 Web 漏洞扫描平台,提供目标管理、漏洞扫描、报告生成等功能。 技术栈: - 后端:Rust + Actix-web + PostgreSQL + SQLx - 前端:React + TypeScript + Ant Design + Vite + Tailwind CSS - 功能模块:认证服务、扫描引擎、任务调度、插件系统 | language: Rust | stars: 1 | forks: 0 | updated 20...
xiabai2004/RayScan
RayScan 2.0 — 开箱即用的 Web 漏洞扫描器 | SQLi/XSS/命令注入/LFI/SSRF/XXE/RCE/API安全 | 多引擎聚合(Nuclei/sqlmap/ffuf)+MSF验证链+Profile扫描配置 | CLI+Web UI双模式 | Metasploitable 2实战验证发现83漏洞 | topics: bug-bounty, command-injection, dvwa, lfi-detectio...
rfgg45634/sftool
一个简易的安全工具,正在不断更新中 | language: Python | stars: 0 | forks: 0 | updated 2026-07-12T00:36:26Z | pushed 2026-07-12T00:36:23Z
JinChengZ18/resume-grill
An Agent Skill for grilling resumes: feed it one or more resume PDFs and it produces a three-piece interview kit: an interview guide, a printable scorecard, and Q&A attack-defense cards.拷打你简历的 Agent Skill:喂进一份或多份简历 PDF,产...
w-sega/Kafka_Scan_Gui
一个基于 Python Tkinter 的 Kafka 图形化测试工具,用于批量检测 Kafka 目标、获取 topic 列表,可选获取 topic 消息详情,在内网攻防中快速证明kafka成果。 | language: Python | stars: 1 | forks: 0 | updated 2026-07-15T16:45:36Z | pushed 2026-07-10T10:55:17Z
SecLeap/offensive-security
攻防与渗透测试 | stars: 1 | forks: 0 | updated 2026-08-06T07:01:12Z | pushed 2026-07-11T05:16:36Z
SecLeap/security-capability
SecLeap 安全能力建设仓库,聚焦攻防研究、漏洞分析、安全运营、应急响应、威胁检测、自动化工具与知识沉淀。 | language: Batchfile | stars: 1 | forks: 0 | updated 2026-08-10T04:55:22Z | pushed 2026-07-11T05:28:32Z
Mrli8848/kali-china-setup
Kali Linux 全方位配置脚本 - 一键换源/汉化/红蓝队工具链/CTF/无线安全 | language: Shell | stars: 0 | forks: 0 | updated 2026-07-20T14:03:36Z | pushed 2026-07-20T14:02:07Z
gogoore/FMxePQAv
【Java计算机毕业设计分享】基于SpringBoot的云安全攻防训练系统,Java开发 Python开发 深度学习 二次开发 毕业设计 实战项目【附源码、文档报告、代码讲解、部署教程、开题、任务书】 | stars: 1 | forks: 0 | updated 2026-07-08T18:08:59Z | pushed 2026-07-08T18:08:37Z