​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-94545
👤 项目作者: EQSTLab
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 07:58:11

📝 项目描述:
Next.js RCE

🔗 点击访问项目地址 GitHub - EQSTLab/CVE-2026-94545: Next.js RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Learn-SecByte-Keyring-SQL-Injection-SQLMap-RCE-Shellcraft-CTF-Labs
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 05:40:05

📝 项目描述:
Hands-on cybersecurity and CTF labs covering Keyring access, source discovery, hidden endpoints, SQL injection, SQLMap, RCE, shell stabilization, shellcraft, credential reuse, and post-exploitation concepts.

🔗 点击访问项目地址 GitHub - sifatnotes/Learn-SecByte-Keyring-SQL-Injection-SQLMap-RCE-Shellcraft-CTF-Labs: Hands-on cybersecurity and CTF labs covering…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: Learn-SecByte-DNS-SSTI-XXE-RCE-Web-Security-CTF-Labs
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 05:47:03

📝 项目描述:
Hands-on cybersecurity and CTF labs covering DNS and subdomain discovery, RCE, template injection, SSTI-to-root, authentication reconnaissance, credential trails, stream investigation, XXE file leaks, XML-based attacks, and hosts-file hijacking.

🔗 点击访问项目地址 GitHub - sifatnotes/Learn-SecByte-DNS-SSTI-XXE-RCE-Web-Security-CTF-Labs: Hands-on cybersecurity and CTF labs covering DNS and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-49869
👤 项目作者: EQSTLab
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 05:39:29

📝 项目描述:
Kestra Unauthenticated RCE

🔗 点击访问项目地址 GitHub - EQSTLab/CVE-2026-49869
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE

📦 项目名称: proofcms
👤 项目作者: pxawtyy
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 21:59:06

📝 项目描述:
A DAST tool to check if a given Wordpress/Joomla application is vulnerable or not, with built-in exploits.

🔗 点击访问项目地址 GitHub - pxawtyy/proofcms: A DAST tool to check if a given Wordpress/Joomla application is vulnerable or not, with built-in exploits.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-87902
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 21:21:19

📝 项目描述:
CVE-2026-87902 — WordPress Core LFI → RCE

🔗 点击访问项目地址 GitHub - MRdark-ops/CVE-2026-87902: CVE-2026-87902 — WordPress Core LFI → RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-38526
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 20:53:05

📝 项目描述:
CVE-2026-38526 - Authenticated RCE exploit for Krayin CRM <= 2.2.x. Upload arbitrary PHP via /admin/tinymce/upload and gain remote code execution. Python PoC for security researchers, CTF players and bug bounty hunters. Tested on HTB Nexus.

🔗 点击访问项目地址 MRdark-ops/CVE-2026-38526
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-87902
👤 项目作者: HackfutSecRoot
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 17:23:15

📝 项目描述:
CVE-2026-87902 — WordPress Core LFI → RCE by Hackfut

🔗 点击访问项目地址 GitHub - HackfutSecRoot/CVE-2026-87902
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Learn-SecByte-Webmin-Rips-SSH-Secrets-CTF-Labs
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 15:26:44

📝 项目描述:
Hands-on Learn SecByte CTF labs covering Webmin security, RCE, reconnaissance, logs, file discovery, SSH keys, secrets, stack investigation, and Rips-themed cybersecurity challenges.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-38526
👤 项目作者: Harry178945
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 15:14:29

📝 项目描述:
CVE-2026-38526 - Authenticated RCE exploit for Krayin CRM <= 2.2.x. Upload arbitrary PHP via /admin/tinymce/upload and gain remote code execution. Python PoC for security researchers, CTF players and bug bounty hunters. Tested on HTB Nexus.

🔗 点击访问项目地址 GitHub - Harry178945/CVE-2026-38526
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: citrix-netscaler-cve-2026-88771-rce
👤 项目作者: techupdate24
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 11:37:06

📝 项目描述:
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

🔗 点击访问项目地址 GitHub - techupdate24/citrix-netscaler-cve-2026-88771-rce: A complete guide and workflow for integrating Agile sprints with DevOps…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-22777
👤 项目作者: e5dfdd568a75282b712b6d93a7a18e12
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 10:47:30

📝 项目描述:
CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303

🔗 点击访问项目地址 GitHub - e5dfdd568a75282b712b6d93a7a18e12/CVE-2026-22777: CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2026-39987-Marimo-Preauth-RCE
👤 项目作者: LaArana12
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 10:07:26

📝 项目描述:
Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab.

🔗 点击访问项目地址 GitHub - LaArana12/CVE-2026-39987-Marimo-Preauth-RCE: Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: SmarterMail-CVE-2026-24423
👤 项目作者: CyberAlp0
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 10:07:08

📝 项目描述:
Exploit for CVE-2026-24423 — a critical unauthenticated RCE in SmarterMail's ConnectToHub API. Affects all builds prior to 9511.

🔗 点击访问项目地址 GitHub - CyberAlp0/SmarterMail-CVE-2026-24423: Exploit for CVE-2026-24423 — a critical unauthenticated RCE in SmarterMail's ConnectToHub…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-100721
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 09:46:59

📝 项目描述:
CVE-2026-100721 PoC: vm2 <3.12.2 NodeVM external allowlist bypass → sandbox escape / host RCE. Local Node lab (evil-left-pad), remote sandbox API mass exploit, colorful CLI. PoCbit — https://pocbit.org/pocs/cve-2026-100721

🔗 点击访问项目地址 GitHub - murrez/CVE-2026-100721: CVE-2026-100721 PoC: vm2 <3.12.2 NodeVM external allowlist bypass → sandbox escape / host RCE.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-88772-POC
👤 项目作者: FollowerSeize
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 09:58:26

📝 项目描述:
CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)

🔗 点击访问项目地址 GitHub - FollowerSeize/CVE-2026-88772-POC: CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: aws-role-to-RCE-exploit-ctf-lab
👤 项目作者: mmerraj
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 09:05:55

📝 项目描述:
AWS Identity & Access Management (IAM): Analyzing IAM policies, finding misconfigurations, and performing user/role privilege escalation.Cloud Reconnaissance: Enumerating public-facing and internal Amazon Web Services (AWS) resources.Exploitation of Cloud Assets: Navigating cloud-native architectures to move laterally, bypass permission boundaries.

🔗 点击访问项目地址 mmerraj/aws-role-to-RCE-exploit-ctf-lab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-82384
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 08:26:05

📝 项目描述:
CVE-2026-82384 PoC: Apache Roller 6.1.5 unauthenticated XML-RPC ex:serializable Java deserialization (pre-auth RCE). Check, ysoserial exploit, mass bulk scanning, colored CLI. PoCbit — https://pocbit.org/pocs/cve-2026-82384

🔗 点击访问项目地址 GitHub - murrez/CVE-2026-82384: CVE-2026-82384 PoC: Apache Roller 6.1.5 unauthenticated XML-RPC ex:serializable Java deserialization…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-6951
👤 项目作者: EQSTLab
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 08:48:36

📝 项目描述:
simple-git RCE

🔗 点击访问项目地址 GitHub - EQSTLab/CVE-2026-6951
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: HTB-Pterodactyl-RCE-CVE-2025-49132
👤 项目作者: symphony2colour
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-28 04:37:51

📝 项目描述:
This repo contains RCE exploit for Pterodactyl htb machine

🔗 点击访问项目地址 GitHub - symphony2colour/HTB-Pterodactyl-RCE-CVE-2025-49132: This repo contains RCE exploit for Pterodactyl htb machine
 
 
Back to Top