📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: firmware-vuln-scanner
👤 项目作者: Ayush-X003
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 20:34:18

📝 项目描述:
Offline static vulnerability scanner for extracted embedded/IoT firmware filesystems

🔗 点击访问项目地址 GitHub - Ayush-X003/firmware-vuln-scanner: Offline static vulnerability scanner for extracted embedded/IoT firmware filesystems
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: joomla-content-editor--RCE
👤 项目作者: ChrisSEC2014
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 20:39:45

📝 项目描述:
无描述

🔗 点击访问项目地址 ChrisSEC2014/joomla-content-editor--RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: TAINT
👤 项目作者: core2du
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 20:38:29

📝 项目描述:
Web pentesting & vulnerability reconnaissance framework with CLI pipeline. Detects SQLi, XSS, CORS misconfigurations, Verb Tampering, and DOM-based flaws. Designed for authorized bug bounty and ethical hacking.

🔗 点击访问项目地址 GitHub - core2du/TAINT: Web pentesting & vulnerability reconnaissance framework with CLI pipeline. Detects SQLi, XSS, CORS misconfigurations…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE
👤 项目作者: absholi7ly
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 20:51:38

📝 项目描述:
CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of empty upload entries (UPLOAD_ERR_NO_FILE). An unauthenticated attacker can submit a multipart

🔗 点击访问项目地址 GitHub - absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE: CVE-2026-32475 The Elementor Pro Forms File Upload…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: XSStriker
👤 项目作者: Mr-Destroyer
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 19:53:06

📝 项目描述:
The best tool for XSS attack

🔗 点击访问项目地址 GitHub - Mr-Destroyer/XSStriker: The best tool for XSS attack
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Fucker
👤 项目作者: Mr-Destroyer
🛠 开发语言: Python
Star数量: 6 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 19:55:26

📝 项目描述:
Fucker is Web Application Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: firmware-vuln-scanner
👤 项目作者: hunter1910
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 19:59:22

📝 项目描述:
Offline static vulnerability scanner for extracted embedded/IoT firmware filesystems

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution

📦 项目名称: linux-server-pentest-lab
👤 项目作者: firatcanbekar
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 16:40:58

📝 项目描述:
Full black-box penetration test against an Ubuntu 22.04 LTS server — recon, dual initial access (Tomcat RCE + Shellshock), SUID privilege escalation, hash cracking, and Nessus credentialed scan. Includes professional pentest report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: automated-vulnerability-scanner
👤 项目作者: gurikaur2
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 18:57:10

📝 项目描述:
Automated Vulnerability Scanner and Remediation Engine built using Spring Boot, React and Chrome Extension

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-65400-poc
👤 项目作者: panchocosil
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 18:23:22

📝 项目描述:
Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.

🔗 点击访问项目地址 GitHub - panchocosil/CVE-2026-65400-poc: Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-J2store-2026
👤 项目作者: murrez
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 18:53:09

📝 项目描述:
PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #POC

📦 项目名称: PANSPHAIRA
👤 项目作者: JoFe2
🛠 开发语言: TypeScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 05:18:20

📝 项目描述:
PanSphaira — open-source local proof of concept for governed AI-agent actions across business systems, with policy, approval, brokered execution, authoritative readback, and receipts.

🔗 点击访问项目地址 GitHub - JoFe2/PANSPHAIRA: PanSphaira — open-source local proof of concept for governed AI-agent actions across business systems…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: ZEROGRAVE
👤 项目作者: sn0x-sharma
🛠 开发语言: HTML
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 18:03:52

📝 项目描述:
A graveyard of critical vulnerabilities I've discovered, along with their PoCs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: aes256_loader
👤 项目作者: bloggins
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 18:04:51

📝 项目描述:
Fully contained AES-256-CBC encrypted shellcode DLL loader with 4 exection methods

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: dsh2shell
👤 项目作者: ChaoMixian
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 17:49:17

📝 项目描述:
Unauthenticated RCE PoC for exposed DeepSeek Harness (dsh) web instances.

🔗 点击访问项目地址 GitHub - ChaoMixian/dsh2shell: Unauthenticated RCE PoC for exposed DeepSeek Harness (dsh) web instances.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVE-2026-76565
👤 项目作者: toanln-cov
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 17:14:25

📝 项目描述:
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

🔗 点击访问项目地址 GitHub - toanln-cov/CVE-2026-76565: Reflected XSS via price_from / price_to Filter Parameters in PhocaCart
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-2026-76564
👤 项目作者: toanln-cov
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 17:16:56

📝 项目描述:
Stored XSS via User-Agent in Admin Order View in PhocaCart

🔗 点击访问项目地址 GitHub - toanln-cov/CVE-2026-76564: Stored XSS via User-Agent in Admin Order View in PhocaCart
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-58455-PoC
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 17:20:39

📝 项目描述:
PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: JCEzploit-CVE-2026-48907
👤 项目作者: CerberusMrXi
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 17:58:54

📝 项目描述:
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.

🔗 点击访问项目地址 GitHub - CerberusMrXi/JCEzploit-CVE-2026-48907: JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907)…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-auth-check
👤 项目作者: OmniCyber-Security
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-21 16:46:51

📝 项目描述:
Burp Suite extension for authorisation testing: replays requests as multiple identities and unauthenticated, with scripted session maintenance for short-lived logins

🔗 点击访问项目地址 GitHub - OmniCyber-Security/burp-auth-check: Burp Suite extension for authorisation testing: replays requests as multiple identities…
Back to Top