GitHub 红队武器库🚨
14.2K subscribers
26 photos
10 videos
26.7K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE #Nuclei

📦 项目名称: CVE-2026-87902
👤 项目作者: Hassham1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 11:54:01

📝 项目描述:
WordPress Core <= 7.1.1 unauthenticated LFI to RCE - validation lab, PoC, nuclei template (GHSA-7hp8-65ch-5whp)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Malware_Detector-YARA_Rules-
👤 项目作者: MonicaMuthu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 12:04:09

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: MicroTrick
👤 项目作者: digiprosec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 12:52:36

📝 项目描述:
cve-2026-86060 PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: GymSIEGE
👤 项目作者: ElenaViewSynthesis
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 12:47:47

📝 项目描述:
▎ Fleet-evaluation harness for security-agent benchmarks (CyberGym-E2E, ExploitGym, ExploitBench), run in real disposable Daytona sandboxes per trial — with Modal-based KVM-capable sandboxes planned for kernel-exploit tasks. Measures agent capability and infra reliability, not simulated.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: campaignhub-lab
👤 项目作者: arslanben
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 13:04:08

📝 项目描述:
CampaignHub DOM XSS CTF lab

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: VoidStrike
👤 项目作者: CypherNova1337
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 13:48:45

📝 项目描述:
AI-assisted remote code execution testing framework - command injection, SSTI, deserialization, JNDI/Log4Shell and file upload, planned and adapted per request.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-94545-nextjs-og-poc
👤 项目作者: Hassham1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 14:52:43

📝 项目描述:
CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j — Next.js next/og ImageResponse SVG injection (Satori, GHSA-wx4j-mvgx-mqwp): isolated Docker validation lab with vulnerable (16.3.5) vs patched (16.3.6) controls, non-destructive Python scanner with pixel-level PNG evidence, and root-cause analysis of the upstream Satori fix. Authorized security research only.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-87902
👤 项目作者: bhideki
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:58:25

📝 项目描述:
CVE-2026-87902: PoC for WordPress's critical path traversal

🔗 点击访问项目地址
👍2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner-Mini-Project-
👤 项目作者: saivardhanlingam1-art
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:43:20

📝 项目描述:
give me jsut what i need to paste in discription A lightweight vulnerability scanner designed to detect common security flaws, open ports, and system misconfigurations.

🔗 点击访问项目地址
👍2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #DOM

📦 项目名称: Manual-Web-Penetration-Testing-and-Core-Vulnerability-Exploitation
👤 项目作者: cyber-Megha
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:46:44

📝 项目描述:
Hands-on manual penetration testing and Proof-of-Concept (PoC) exploitation framework targeting OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF, Path Traversal) via advanced payload injection and DOM weaponization.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Nuclei

📦 项目名称: CVE-2026-89274-wp-recipe-maker-poc
👤 项目作者: Hassham1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 16:29:11

📝 项目描述:
CVE-2026-89274 — WP Recipe Maker <= 10.8.1 arbitrary shortcode execution via rating-comment reviewBody (CVSS 9.1): Docker validation lab with vulnerable (10.8.1) vs patched (10.8.2) controls, Python PoC proving server-side shortcode execution in recipe JSON-LD, nuclei version screen. Authorized security research only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Source-Code-Auditing-Lab
👤 项目作者: steelo-cmg
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 16:44:03

📝 项目描述:
A technical vulnerability lab modeling unvalidated user input vectors, remote code execution (RCE) flaws using eval(), and structural string sanitisation fixes.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: wifinet-creds-inspector
👤 项目作者: Nikita465-dev
🛠 开发语言: HTML
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 17:05:56

📝 项目描述:
Wi-Fi Password Auditor: Secure Credential Recovery & Network Vulnerability Scanner for 2026

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner
👤 项目作者: thirunika24
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 16:54:24

📝 项目描述:
A lightweight Python-based vulnerability scanner for authorized local targets.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Yara-malware-detection-lab
👤 项目作者: mohammedabrar-27
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 17:56:01

📝 项目描述:
YARA rules for identifying suspicious file patterns

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-2026-88997
👤 项目作者: pervinzahidli
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 17:17:03

📝 项目描述:
JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: shellforge
👤 项目作者: erengng
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 17:04:20

📝 项目描述:
ShenCode 2026: Next-Gen Shellcode Builder & Payload Converter Suite

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ts-libs
👤 项目作者: spy4x
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:23:18

📝 项目描述:
Framework-agnostic TypeScript libraries for Deno, published to JSR as @spy4x/*: validation, platform primitives, server adapters, net/SSRF guards, email, time, realtime, integrations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: dotnet-webhooks
👤 项目作者: ericksonlopezf
🛠 开发语言: C#
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 14:39:28

📝 项目描述:
Production-ready webhook engine for .NET 8/9/10: resilient outbound delivery with Polly v8 & socket-level SSRF mitigation, Redis distributed DLQ & anti-replay defense, and ASP.NET Core inbound verification middleware with Native AOT & OpenTelemetry.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC #Remote Code Execution

📦 项目名称: vercel-skills-poc
👤 项目作者: 3bkader-gpt
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 17:47:11

📝 项目描述:
Security Advisory & Proof of Concept: Remote Code Execution (RCE) via Unsafe Skill Frontmatter Evaluation in Agentic AI Frameworks.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2024-37054
👤 项目作者: BardLaudian
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 17:08:56

📝 项目描述:
Generic PoC for MLflow pickle deserialization RCE (CVE-2024-37054-style). Poisons a registered model via the MLflow REST API to achieve code execution when the model is loaded.

🔗 点击访问项目地址