📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: websec-scout
👤 项目作者: jordannpearce
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 23:26:13

📝 项目描述:
Next.js domain security scanner using Scrappey — headers, XSS posture, WHOIS, email auth, stack fingerprints, and crawls.

🔗 点击访问项目地址 GitHub - jordannpearce/websec-scout: Next.js domain security scanner using Scrappey — headers, XSS posture, WHOIS, email auth,…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-17544
👤 项目作者: r2qa
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 22:28:52

📝 项目描述:
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.

🔗 点击访问项目地址 GitHub - r2qa/CVE-2026-17544: CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: patch-icloud-secd-com
👤 项目作者: kiiki290
🛠 开发语言: PowerShell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:01:16

📝 项目描述:
修复 Windows 版 iCloud 密码扩展验证码弹窗失效:WindowsApps 权限提权状态下安装导致 secd 打包 COM 挂载失效(急救补丁 / 治本还原权限+重装)| Fix iCloud Passwords popup failure on Windows: broken packaged-COM mount caused by installing with elevated WindowsApps permissions (first-aid patch / permanent ACL restore + reinstall)

🔗 点击访问项目地址 GitHub - kiiki290/patch-icloud-secd-com: 修复 Windows 版 iCloud 密码扩展验证码弹窗失效:WindowsApps 权限提权状态下安装导致 secd 打包 COM 挂载失效(急救补丁 / 治本还原权限+重装)|…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: XSS_Labs
👤 项目作者: NazaninNazari
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 21:57:27

📝 项目描述:
Hands-on XSS labs for learning, practicing, and understanding Cross-Site Scripting vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-47103-python-statemachine-rce
👤 项目作者: SaiTeja-Erukude
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 21:29:01

📝 项目描述:
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.

🔗 点击访问项目地址 GitHub - SaiTeja-Erukude/CVE-2026-47103-python-statemachine-rce: Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr>…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-9147-uproot-rce
👤 项目作者: SaiTeja-Erukude
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 21:58:48

📝 项目描述:
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.

🔗 点击访问项目地址 GitHub - SaiTeja-Erukude/CVE-2026-9147-uproot-rce: uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Confluence #漏洞

📦 项目名称: tropatt-module-confluence-migration
👤 项目作者: Anton-Barinov
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 20:27:09

📝 项目描述:
Migrates spaces and pages from Confluence Cloud into the TropaTT knowledge base.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: orca-poc-target
👤 项目作者: junninho-orca
🛠 开发语言: HCL
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 20:09:29

📝 项目描述:
Deliberately vulnerable demo target for the AI-remediation POC (see ai-remediation-demo)

🔗 点击访问项目地址 GitHub - junninho-orca/orca-poc-target: Deliberately vulnerable demo target for the AI-remediation POC (see ai-remediation-demo)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: YARAdec
👤 项目作者: rdx0120
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 20:50:52

📝 项目描述:
Decompiles compiled YARA rules (.yarc) back to source — supports YARA 4.3–4.5.8

🔗 点击访问项目地址 GitHub - rdx0120/YARAdec: Decompiles compiled YARA rules (.yarc) back to source — supports YARA 4.3–4.5.8
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #POC

📦 项目名称: aquila-graph-poc
👤 项目作者: eagle-head
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 21:00:02

📝 项目描述:
Reproducible POC for combining static and runtime Java facts in a provenance-preserving graph.

🔗 点击访问项目地址 GitHub - eagle-head/aquila-graph-poc: Reproducible POC for combining static and runtime Java facts in a provenance-preserving graph.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-47117-openmed-rce
👤 项目作者: SaiTeja-Erukude
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 20:27:30

📝 项目描述:
OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-9830
👤 项目作者: opaxial
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 20:59:04

📝 项目描述:
CVE-2026-9830 Proof of Concept

🔗 点击访问项目地址 GitHub - opaxial/CVE-2026-9830: CVE-2026-9830 Proof of Concept
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #Exploit

📦 项目名称: defcon-badge-0day
👤 项目作者: Trinity-SYT-SECURITY
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:49:49

📝 项目描述:
DEF CON 34 badge

🔗 点击访问项目地址 GitHub - Trinity-SYT-SECURITY/defcon-badge-0day: DEF CON 34 badge
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: websec-scanner
👤 项目作者: HamzaSudozai
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:11:42

📝 项目描述:
Passive web vulnerability scanner with OWASP Top 10 checks and generates HTML/PDF reports. Authorized security testing only.

🔗 点击访问项目地址 GitHub - HamzaSudozai/websec-scanner: Passive web vulnerability scanner with OWASP Top 10 checks and generates HTML/PDF reports.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: CVE-2026-20896-Gitea-Authentication-Bypass
👤 项目作者: judgedbykira
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 19:05:05

📝 项目描述:
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.

🔗 点击访问项目地址 GitHub - judgedbykira/CVE-2026-20896-Gitea-Authentication-Bypass: An explanation and PoC to exploit CVE-2026-20896 Authentication…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: credjack
👤 项目作者: maximalfocus
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:29:37

📝 项目描述:
A local, container-only educational demonstration of SSRF to a cloud instance metadata service (CWE-918 / OWASP A10:2021), through to credential replay, and the resolved-address control that stops it. Everything is fictional and runs only on your machine.

🔗 点击访问项目地址 GitHub - maximalfocus/credjack: A local, container-only educational demonstration of SSRF to a cloud instance metadata service…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: PassiveSight
👤 项目作者: yadavnikhil17102004
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:07:30

📝 项目描述:
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

🔗 点击访问项目地址 GitHub - yadavnikhil17102004/PassiveSight: AI-powered vulnerability scanner extension for Burp Suite with multi-provider support…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: zig0.16.0-shellcode
👤 项目作者: kingwei123
🛠 开发语言: Zig
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:59:42

📝 项目描述:
无描述

🔗 点击访问项目地址 kingwei123/zig0.16.0-shellcode
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: MouseServer-1.7.8.5-RCE
👤 项目作者: mermehr
🛠 开发语言: PowerShell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 17:58:08

📝 项目描述:
PoC for CVE-2022-3218

🔗 点击访问项目地址 GitHub - mermehr/MouseServer-1.7.8.5-RCE: PoC for CVE-2022-3218
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #CVE

📦 项目名称: VulnTracer
👤 项目作者: rockmelodies
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 17:21:22

📝 项目描述:
Vuln(漏洞)+ Tracer(追踪器),强调 AI 对污点数据流的深度追踪、对攻击面的精准测绘能力,直击代码审计挖 CVE 的核心技术逻辑,专业感强,适合主打审计深度的技术定位。

🔗 点击访问项目地址 rockmelodies/VulnTracer
Back to Top