📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE

📦 项目名称: CVE-2025-27520
👤 项目作者: electricsheep08
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 13:59:56

📝 项目描述:
exploit for CVE-2025-27520 A Remote Code Execution (RCE) vulnerability caused by insecure deserialization in the latest version (v1.4.2) of BentoML. It allows any unauthenticated user to execute arbitrary code on the server. It exists an unsafe code segment in serde.py. This vulnerability is fixed in 1.4.3.

🔗 点击访问项目地址 GitHub - electricsheep08/CVE-2025-27520: exploit for CVE-2025-27520 A Remote Code Execution (RCE) vulnerability caused by insecure…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: oidc-ssrf-poc-8706363
👤 项目作者: or-akl
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 13:04:39

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - or-akl/oidc-ssrf-poc-8706363
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: PatrowlIntelLabs
👤 项目作者: Patrowl
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 12:26:02

📝 项目描述:
Weaponized-but-safe: Dockerized vulnerable apps + battle-tested Nuclei templates for real-world web & Internet-facing CVEs. Original research by Patrowl.

🔗 点击访问项目地址 GitHub - Patrowl/PatrowlIntelLabs: Weaponized-but-safe: Dockerized vulnerable apps + battle-tested Nuclei templates for real-world…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: PoC-CVE-2026-46331
👤 项目作者: cherrycherrymay
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 13:02:55

📝 项目描述:
Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)

🔗 点击访问项目地址 GitHub - cherrycherrymay/PoC-CVE-2026-46331: Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: XSS-Immune-JWT-Authentication-Architecture
👤 项目作者: IamAhsan1
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 12:59:37

📝 项目描述:
A highly secure, production-ready authentication system utilizing a Double HttpOnly Cookie architecture to render user sessions 100% immune to Cross-Site Scripting (XSS) attacks.

🔗 点击访问项目地址 GitHub - IamAhsan1/XSS-Immune-JWT-Authentication-Architecture: A highly secure, production-ready  authentication system utilizing…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Application-Vulnerability-Scanner
👤 项目作者: poojanenavath123
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 12:40:34

📝 项目描述:
Python-based web application vulnerability scanner using Requests and BeautifulSoup for educational and authorized security testing.

🔗 点击访问项目地址 GitHub - poojanenavath123/Web-Application-Vulnerability-Scanner: Python-based web application vulnerability scanner using Requests…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: my-nuclei-templates
👤 项目作者: Tjalling112
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 11:57:41

📝 项目描述:
My personal Nuclei vulnerability templates

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: waf-bypass-automation
👤 项目作者: viktorefimov2002-bot
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 12:05:35

📝 项目描述:
discover nemesida/waf-bypass report and recheck detected bypassed cURL requests to write SecRules for them

🔗 点击访问项目地址 GitHub - viktorefimov2002-bot/waf-bypass-automation: discover nemesida/waf-bypass report and recheck detected bypassed cURL requests…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-65650
👤 项目作者: swornim619
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 11:55:58

📝 项目描述:
PoC for CVE-2026-65650 - Elgg avatar upload DoS

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-2026-65761
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 11:07:18

📝 项目描述:
EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)

🔗 点击访问项目地址 GitHub - shinthink/CVE-2026-65761: EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-scanner-
👤 项目作者: vikirocker09
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 11:06:03

📝 项目描述:
Vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: MODERN-BLOG
👤 项目作者: Punith2412
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 10:55:03

📝 项目描述:
A full-stack Flask blog CMS with AI-assisted content tools (Groq, Anthropic), CKEditor rich-text posts, an in-browser Python/JS code playground, and an interactive quiz system. Hardened via automated Selenium testing: fixed broken access control, stored XSS, and 500 errors; added RBAC, RSS/sitemap, rate limiting, and real image uploads.

🔗 点击访问项目地址 Punith2412/MODERN-BLOG
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-63030
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 10:50:32

📝 项目描述:
WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026-60137)

🔗 点击访问项目地址 GitHub - shinthink/CVE-2026-63030: WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: yara2stix
👤 项目作者: muchdogesec
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 09:50:45

📝 项目描述:
A command line tool that converts the YARA Rules into STIX 2.1 Objects.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-9198
👤 项目作者: ywh-jfellus
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 09:42:55

📝 项目描述:
Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass

🔗 点击访问项目地址 GitHub - ywh-jfellus/CVE-2026-9198: Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: Advanced-SOC-and-Threat-Detection
👤 项目作者: ayushkp930
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 09:02:24

📝 项目描述:
SOC lab for high-fidelity threat hunting: detects Sliver C2 beacons via Zeek/Suricata, handles fileless LotL attacks with ELK/Sigma, deploys Python-Volatility for memory forensics, tracks DNS/ICMP exfiltration in Splunk, and utilizes FSRM canary files with PowerShell triggers for automated open-source ransomware containment & host isolation.

🔗 点击访问项目地址 GitHub - ayushkp930/Advanced-SOC-and-Threat-Detection: SOC lab for high-fidelity threat hunting: detects Sliver C2 beacons via…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: cve-2021-44228-log4shell_rce_reproduction
👤 项目作者: razureink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 08:52:12

📝 项目描述:
CVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE

🔗 点击访问项目地址 GitHub - razureink/cve-2021-44228-log4shell_rce_reproduction: CVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: nuclei-tripse
👤 项目作者: Yuri0x
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 08:23:33

📝 项目描述:
my bounty template

🔗 点击访问项目地址 GitHub - Yuri0x/nuclei-tripse: my bounty template
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: xuanjian
👤 项目作者: yzdily
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 08:44:28

📝 项目描述:
一个会操作浏览器、会抓包改包、会按照方法论执行、会自己验证漏洞的自动化渗透测试 Agent

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: 550W-Godel-Jailbreak-Preview
👤 项目作者: KangBo1118
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-24 08:36:58

📝 项目描述:
550W 哥德尔越狱 - 逻辑型目标溢出漏洞预览 ## 🔒 披露状态 - 已提交厂商安全中心 (2026-05-13) - 已提交360SRC (2026-05-13) - 等待官方修复 - 🔒 完整复现步骤暂不公开

🔗 点击访问项目地址 GitHub - KangBo1118/550W-Godel-Jailbreak-Preview: 550W 哥德尔越狱 - 逻辑型目标溢出漏洞预览  ## 🔒 披露状态 - ✅ 已提交厂商安全中心 (2026-05-13) - ✅ 已提交360SRC…
Back to Top