​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: ShallowEnd-Plugins
👤 项目作者: BKLockly
🛠 开发语言: Zig
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 04:02:10

📝 项目描述:
Official plugin monorepo for ShallowEnd — Zig + Tokota Node.js native addons for post-exploitation (BOF, recon, file ops, sensitive data discovery)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-34990-CUPS-LPE-PoC
👤 项目作者: Noorkhalel
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 03:41:50

📝 项目描述:
Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite.

🔗 点击访问项目地址 GitHub - Noorkhalel/CVE-2026-34990-CUPS-LPE-PoC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #Exploit #CVE

📦 项目名称: vuln-search-skill
👤 项目作者: ming-14
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 01:38:11

📝 项目描述:
多源漏洞搜索 Skill | A AI Agent skill for CVE vulnerability searching, exploit discovery, and privilege escalation research. Integrates NVD, Exploit-DB, CISA-KEV, and Vulners databases.

🔗 点击访问项目地址 GitHub - ming-14/vuln-search-skill: 多源漏洞搜索 Skill | A AI Agent skill for CVE vulnerability searching, exploit discovery, and privilege…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-78006-CVE-2026-78159
👤 项目作者: antid00t
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 00:53:48

📝 项目描述:
CVE-2026-78006 + CVE-2026-78159 Mass Exploit

🔗 点击访问项目地址 GitHub - antid00t/CVE-2026-78006-CVE-2026-78159: The Events Calendar Wordpress Plugin Mass Exploit CVE-2026-78006 & CVE-2026-78159
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-87902-exploit
👤 项目作者: Maalfer
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 20:52:51

📝 项目描述:
Exploit para explotar la vulnerabilidad CVE-2026-87902 que se acontece en el core de WordPress

🔗 点击访问项目地址 GitHub - Maalfer/CVE-2026-87902-exploit: Exploit para explotar la vulnerabilidad CVE-2026-87902 que se acontece en el core de WordPress
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-2026-67279-86060-Toolkit
👤 项目作者: tc4dy
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 12:03:47

📝 项目描述:
🛡️ CVE-2026-67279 + CVE-2026-86060 – MikroTrick MikroTik RouterOS SSH Pre-Auth Takeover (CVSS 9.2) | Red/Blue Team suite. 2 tools: Full Exploit (rekey bypass, fd-2 policy swap, full-admin shell, plant, mass scan, SOCKS5/Tor, stealth) & SafeDetect (banner/version audit, IoC guidance, JSON/CSV/HTML). Use Ethically & Safety only.

🔗 点击访问项目地址 GitHub - tc4dy/CVE-2026-67279-86060-Toolkit: CVE-2026-67279 + CVE-2026-86060 – MikroTrick MikroTik RouterOS SSH Pre-Auth Takeover…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: YellowKey-BitLocker-CVE-2026-45585
👤 项目作者: YellowKeyBitLocker-CVE
🛠 开发语言: C++
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 08:32:41

📝 项目描述:
YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own. Extract and run. Official free download. Download:➧

🔗 点击访问项目地址 GitHub - YellowKeyBitLocker-CVE/YellowKey-BitLocker-CVE-2026-45585: YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: cve-2026-85706
👤 项目作者: unh00k3d
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 08:57:09

📝 项目描述:
CVE-2026-85706 — GitLab unauthenticated arbitrary file read (CVSS 10.0). Root-cause analysis, vulnerable Docker lab, and PoC.

🔗 点击访问项目地址 GitHub - unh00k3d/cve-2026-85706: CVE-2026-85706 — GitLab unauthenticated arbitrary file read (CVSS 10.0). Root-cause analysis…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #漏洞 #Exploit #RCE

📦 项目名称: webshell_seo_0day
👤 项目作者: MDhlzG0b
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:23:44

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - MDhlzG0b/webshell_seo_0day
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #漏洞 #Exploit #RCE

📦 项目名称: webshell_seo_0day
👤 项目作者: sqkBpI7t
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:23:54

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - sqkBpI7t/webshell_seo_0day
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE #Nuclei

📦 项目名称: CVE-2026-63030
👤 项目作者: langz337
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 18:33:01

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - langz337/CVE-2026-63030
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: Exploit-Index
👤 项目作者: msdbg
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 17:52:50

📝 项目描述:
Exploit Index provides a searchable, version-wise database of High and Critical CVEs across major enterprise products, with Proof of Concept (PoC) exploit links and CISA Known Exploited Vulnerability (KEV) tracking, for security researchers.

🔗 点击访问项目地址 msdbg/Exploit-Index
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: rainbet-casino-exploit
👤 项目作者: zephyrcore
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 14:03:01

📝 项目描述:
A race condition in rainbet.com allowing to predict outcomes of specified games ( original ). POC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-29053
👤 项目作者: K3ysTr0K3R
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 13:24:36

📝 项目描述:
CVE-2026-29053 - Ghost CMS < 6.19.0 - Authenticated Remote Code Execution via Malicious Theme

🔗 点击访问项目地址 GitHub - K3ysTr0K3R/CVE-2026-29053
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #漏洞 #利用

📦 项目名称: opace6-cve-2026-64560
👤 项目作者: qingle009
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 12:40:00

📝 项目描述:
OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: POC-WP-CORE-CVE-2026-93485
👤 项目作者: 686f6c61
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 12:55:46

📝 项目描述:
Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verificada, control 7.1.1 y la vía Post2Shell

🔗 点击访问项目地址 GitHub - 686f6c61/POC-WP-CORE-CVE-2026-93485: Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: zenfone9-ghostlock
👤 项目作者: CKwasd
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 11:40:13

📝 项目描述:
CVE-2026-43499 (GhostLock) exploit for ASUS Zenfone 9 (SM8475, GKI 5.10.205) + KernelSU late-load.

🔗 点击访问项目地址 GitHub - CKwasd/zenfone9-ghostlock: CVE-2026-43499 (GhostLock) exploit for ASUS Zenfone 9 (SM8475, GKI 5.10.205) + KernelSU late…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-13249
👤 项目作者: murrez
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 11:59:57

📝 项目描述:
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC

🔗 点击访问项目地址 GitHub - murrez/CVE-2026-13249: Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-18143
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 08:00:40

📝 项目描述:
Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_file() with attacker-controlled .php filenames into web-accessible RFQ temp storage (popup quote flow required). CVSS 9.8. Python check/exploit PoC → pocbit.org/pocs/cve-2026-18143

🔗 点击访问项目地址 GitHub - murrez/CVE-2026-18143: Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-14281
👤 项目作者: langz337
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 07:15:04

📝 项目描述:
CVE-2026-14281

🔗 点击访问项目地址 GitHub - langz337/CVE-2026-14281: CVE-2026-14281
 
 
Back to Top