📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: IIT-Jammu-Final-Project
👤 项目作者: Krishna-The-Developer
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:48:50
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: IIT-Jammu-Final-Project
👤 项目作者: Krishna-The-Developer
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:48:50
📝 项目描述:
VulnScan is a multi-threaded network vulnerability scanner built in Python. It scans common or full port ranges (1–65535), detects open ports, applies rule-based security checks, calculates risk scores, and generates detailed HTML reports. Designed with a Tkinter GUI for educational and academic cybersecurity projects.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #文件上传 #漏洞
📦 项目名称: Class03-File-Upload-Security
👤 项目作者: fankfc
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:25:59
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #文件上传 #漏洞
📦 项目名称: Class03-File-Upload-Security
👤 项目作者: fankfc
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:25:59
📝 项目描述:
Flask 文件上传功能实现与安全加固 — 扩展名白名单、PIL 内容校验、UUID 重命名、速率限制🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #CVE #POC
📦 项目名称: CVE-2025-64512
👤 项目作者: BardLaudian
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:08:37
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #CVE #POC
📦 项目名称: CVE-2025-64512
👤 项目作者: BardLaudian
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:08:37
📝 项目描述:
CLI wrapper around the official PoC for CVE-2025-64512 — pdfminer.six insecure pickle deserialization via crafted PDF (RCE)🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #漏洞 #EXP #POC
📦 项目名称: fastjsonRCE-66-83
👤 项目作者: vv4ke
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:56:46
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #漏洞 #EXP #POC
📦 项目名称: fastjsonRCE-66-83
👤 项目作者: vv4ke
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:56:46
📝 项目描述:
Fastjson 1.2.66 ~ 1.2.83 版本中,`checkAutoType` 方法在处理 `@JSONType` 注解时存在缺陷。通过构造特殊的 `@type` 值,可以绕过安全检查,利用 `LaunchedURLClassLoader` 从远程加载恶意类并执行。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #CVE
📦 项目名称: drupal-openai-provider-ssrf-cve-2026-13233
👤 项目作者: KuniNogu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:42:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #CVE
📦 项目名称: drupal-openai-provider-ssrf-cve-2026-13233
👤 项目作者: KuniNogu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:42:22
📝 项目描述:
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #漏洞 #扫描
📦 项目名称: SentinelScan
👤 项目作者: gutddts
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:08
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #漏洞 #扫描
📦 项目名称: SentinelScan
👤 项目作者: gutddts
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:08
📝 项目描述:
🔍 全栈漏洞扫描管理平台 — React + FastAPI,支持端口扫描/HTTP头检测/SSL验证/漏洞检测,可视化仪表盘与PDF报告🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Bypass #WAF
📦 项目名称: agentrouter-setup-guide
👤 项目作者: marko1olo
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:00:33
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Bypass #WAF
📦 项目名称: agentrouter-setup-guide
👤 项目作者: marko1olo
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:00:33
📝 项目描述:
Complete guide to run Claude Code CLI & VS Code with AgentRouter using a WAF bypass proxy🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-49099
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:20:39
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-49099
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:20:39
📝 项目描述:
PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and overrides the producer's configured SOQL (SOQL injection / broken access control). Fixed in 4.14.8/4.18.3/4.21.0.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-49365
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:56
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-49365
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:56
📝 项目描述:
PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #CVE
📦 项目名称: user999leak
👤 项目作者: congyu-bot
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:58:17
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #CVE
📦 项目名称: user999leak
👤 项目作者: congyu-bot
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:58:17
📝 项目描述:
CVE-2025-21479_Exploit.bin🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Nuclei #templates
📦 项目名称: security-templates
👤 项目作者: FURQANAHMAD34
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:49:40
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Nuclei #templates
📦 项目名称: security-templates
👤 项目作者: FURQANAHMAD34
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:49:40
📝 项目描述:
DAST and SAST bug-bounty automation toolkit (secsuite.sh).🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit #RCE
📦 项目名称: n8n-cve-2026-21858
👤 项目作者: qianlijaingshan
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:56:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit #RCE
📦 项目名称: n8n-cve-2026-21858
👤 项目作者: qianlijaingshan
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:56:22
📝 项目描述:
CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: C52-CRUNCH-MALWARE
👤 项目作者: CODECRUNCHWORLDWIDE
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:51:55
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: C52-CRUNCH-MALWARE
👤 项目作者: CODECRUNCHWORLDWIDE
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:51:55
📝 项目描述:
A free, open-source 12-week course on taking malware apart safely: static and dynamic analysis, disassembly, sandboxing, and YARA — strict🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Bypass #WAF
📦 项目名称: Script
👤 项目作者: hemalathasriram96-pentester
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:59:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Bypass #WAF
📦 项目名称: Script
👤 项目作者: hemalathasriram96-pentester
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:59:21
📝 项目描述:
A Python script for vulnerability scanning with double encoding and WAF bypass capabilities.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #C2 #Beacon
📦 项目名称: dns-https-c2-ueba-detection
👤 项目作者: Sushanth2624
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:56:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #C2 #Beacon
📦 项目名称: dns-https-c2-ueba-detection
👤 项目作者: Sushanth2624
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:56:21
📝 项目描述:
Capstone 2 — Behavioral Detection of Hidden DNS/HTTPS C2 Using UEBA and Multi-Indicator Analysis. All 7 phases (0-6) complete; deployed end-to-end (Zeek/Suricata/ES/Kibana). Result C>B>A: F1 1.00 vs 0.80 vs 0.67.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Ai-assited-client-side-web-vulnerability-scanner
👤 项目作者: Yuva-shreee
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 06:37:54
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Ai-assited-client-side-web-vulnerability-scanner
👤 项目作者: Yuva-shreee
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 06:37:54
📝 项目描述:
Developed a client-side Web Vulnerability Scanner that analyzes HTML and JavaScript to detect security issues like XSS, insecure eval(), and data exposure. Implemented DOM parsing, AST analysis, and OWASP-based risk scoring with automated fix suggestions and secure coding guidance.🔗 点击访问项目地址