📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #RCE

📦 项目名称: aig-shields-up-cybersecurity
👤 项目作者: alainmartar
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:25:39

📝 项目描述:
Cybersecurity virtual experience projects covering Log4j vulnerability response and ransomware recovery with Python.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CyberPanel-Authenticated-RCE
👤 项目作者: dennywise
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 20:38:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - dennywise/CyberPanel-Authenticated-RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: UBITQUITY-GeoServer-Security-Patch
👤 项目作者: ubitquity
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:49:20

📝 项目描述:
An emergency security patch by UBITQUITY to mitigate the unauthenticated SQL injection zero-day vulnerability in GeoServer's jsonArrayContains function. This hotfix sanitizes input parameters for PostGIS and Oracle DataStores to prevent potential Remote Code Execution (RCE).

🔗 点击访问项目地址 GitHub - ubitquity/UBITQUITY-GeoServer-Security-Patch: An emergency security patch by UBITQUITY to mitigate the unauthenticated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2015-1925.RCE
👤 项目作者: damariion
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 19:17:47

📝 项目描述:
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: dsh-security-pocs
👤 项目作者: zzszmyf
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 14:55:00

📝 项目描述:
PoCs for three vulnerabilities (plus one chained exploit) in DeepSeek Harness: !!js config execution, read-only sandbox full-fs reads, vm sandbox exec escape → unconfined host RCE

🔗 点击访问项目地址 GitHub - zzszmyf/dsh-security-pocs: PoCs for three vulnerabilities (plus one chained exploit) in DeepSeek Harness: !!js config…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2026-33017
👤 项目作者: lxxexxbxx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 14:06:10

📝 项目描述:
CVE-2026-33017: Langflow Unauthenticated RCE PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-25938-FUXA-Unauthenticated-RCE
👤 项目作者: judgedbykira
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 13:56:16

📝 项目描述:
An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

🔗 点击访问项目地址 GitHub - judgedbykira/CVE-2026-25938-FUXA-Unauthenticated-RCE: An explanation and PoC to exploit CVE-2026-25938 Unauthenticated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: wp2shell-Exploit-Waf-Bypass
👤 项目作者: interim-embryoniccell971
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 09:14:05

📝 项目描述:
Exploit WordPress pre-auth RCE vulnerabilities with automated WAF bypass to gain unauthenticated shell access.

🔗 点击访问项目地址 GitHub - interim-embryoniccell971/wp2shell-Exploit-Waf-Bypass
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46

📝 项目描述:
OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried in normal business logic — practice source-code review.

🔗 点击访问项目地址 GitHub - JinBaiWansec/sentinelhub: OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-14282
👤 项目作者: nullwhisper
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 00:27:31

📝 项目描述:
GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)

🔗 点击访问项目地址 GitHub - nullwhisper/CVE-2026-14282: GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-69263
👤 项目作者: leoelsolh
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 12:25:22

📝 项目描述:
MCP environment-variable blocklist bypass leads to unauthenticated RCE in Flowise 3.1.1

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE #POC

📦 项目名称: PluckCMS-CSRF-RCE
👤 项目作者: IlhomjonR
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 12:02:34

📝 项目描述:
CVE-2026-70376 — Pluck CMS site-wide CSRF (fail-open Referer check) → RCE via double-extension upload. CWE-352/434, CVSS 8.0. Advisory + PoC by @IlhomjonR.

🔗 点击访问项目地址 GitHub - IlhomjonR/PluckCMS-CSRF-RCE: Pluck CMS site-wide CSRF (fail-open Referer check) → RCE via double-extension upload. PT…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: ssti-labs
👤 项目作者: Caxtiq
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 14:34:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Caxtiq/ssti-labs
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: CodeForge-RCE
👤 项目作者: DevXDividends
🛠 开发语言: Jupyter Notebook
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 07:36:48

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - DevXDividends/CodeForge-RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: MySQL-Remote-Root-Code-Execution
👤 项目作者: Ashrafdev
🛠 开发语言: Python
Star数量: 9 | 🍴 Fork数量: 9
📅 更新时间: 2026-08-12 06:00:42

📝 项目描述:
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.

🔗 点击访问项目地址 GitHub - Ashrafdev/MySQL-Remote-Root-Code-Execution: 0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: trustload
👤 项目作者: jay-tank
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:39:53

📝 项目描述:
A zero-config Python AST linter that flags unsafe loading of an ML model/artifact (torch.load without weights_only, pickle/joblib/dill.load, np.load allow_pickle, keras load_model, yaml.load) - arbitrary code execution (CWE-502), the model-supply-chain RCE class. Points you at weights_only=True / safetensors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: rules-cuda-comment-trigger-rce-poc
👤 项目作者: 2423gen-stack
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:56:06

📝 项目描述:
Responsible PoC for a missing-authorization-check comment-triggered RCE finding in bazel-contrib/rules_cuda integration-tests.yaml (reported to Google Bug Hunters OSS VRP)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE

📦 项目名称: CVE-2025-55182-Exploit
👤 项目作者: dotnetguard
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:01:39

📝 项目描述:
CVE-2025-55182 — Next.js Flight Deserialization RCE exploit with interactive shell, single-command execution and multi-payload reverse shell chain. For authorized penetration testing only.

🔗 点击访问项目地址 GitHub - dotnetguard/CVE-2025-55182-Exploit: CVE-2025-55182 — Next.js Flight Deserialization RCE exploit with interactive shell…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2022-35914-RCE
👤 项目作者: cyb3rk0ala
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 15:48:33

📝 项目描述:
PoC exploit for CVE-2022-35914 — GLPI htmLawed command injection, command execution, and reverse shell support.

🔗 点击访问项目地址 GitHub - cyb3rk0ala/CVE-2022-35914-RCE: PoC exploit for CVE-2022-35914 — GLPI htmLawed command injection, command execution, and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: RCE-Exploits
👤 项目作者: rikgdi
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 10:55:01

📝 项目描述:
Here You Can Find Lots of Windows Remote Code Execution(RCE) Exploits

🔗 点击访问项目地址 GitHub - rikgdi/RCE-Exploits: Here You Can Find Lots of Windows Remote Code Execution(RCE) Exploits
 
 
Back to Top