GitHub 红队武器库🚨
14.2K subscribers
26 photos
9 videos
26.8K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SentinelAPI
👤 项目作者: tanishqueagrawal
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 06:16:20

📝 项目描述:
Zero-Trust API Vulnerability Scanner for automated API security analysis.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-93399
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:53:48

📝 项目描述:
Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointments; bookly_rollback_order cancels/deletes non-completed bookings. CVSS 9.1. Python check/exploit PoC — pocbit.org/pocs/cve-2026-93399

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-89055
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:49:27

📝 项目描述:
Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_submit with arbitrary Media Library attachment IDs in items[].media. Linked files are permanently deleted when the review comment is purged. Python check/exploit PoC (PoCbit catalog).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-14281
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:44:09

📝 项目描述:
Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields → admin. Python check/exploit PoC (PoCbit).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnlock
👤 项目作者: sriharifortitude
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 08:39:20

📝 项目描述:
Known-vulnerability scanner for npm, Go and Python lockfiles, against the real OSV.dev database. Real CVSS v3.1 scoring, waivers, SARIF. Python, MIT.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: SSRF3r
👤 项目作者: MaestraSoprano
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 08:24:42

📝 项目描述:
无描述

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: jack-sparrow
👤 项目作者: Pabl0l
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:37:14

📝 项目描述:
web hacking sharp-tool kit. XSS, SSRF, IDOR...

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghostlock-mrx-w09
👤 项目作者: 0ch4
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 09:50:19

📝 项目描述:
CVE-2026-43499 (GhostLock) port: working root on the Huawei MatePad Pro MRX-W09 (Kirin 990, EMUI 11, Linux 4.14.116) - disassembly-proven write primitive, perf cred leak, and a source-derived HKIP bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-fast-templates
👤 项目作者: reewardius
🛠 开发语言: Unknown
⭐ Star数量: 21 | 🍴 Fork数量: 8
📅 更新时间: 2026-09-25 09:52:14

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: smoothwall-express-dhcp-static-gui-fixes
👤 项目作者: petter5
🛠 开发语言: Perl
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 09:45:35

📝 项目描述:
Bug fixes for Smoothwall Express 3.1's DHCP static-assignments GUI (garbled IP/MAC display, a related stored-XSS, and stale Active status), found while running the DHCP-WoL mod.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: Kestra-cve-2026-53576
👤 项目作者: AtlasVector
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:24:11

📝 项目描述:
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common Docker-socket misconfiguration turns container-root into full host compromise.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #CVE

📦 项目名称: watchdog
👤 项目作者: impressionistic-permeation7619
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:00:15

📝 项目描述:
Automate OSINT data collection and case management with machine-driven monitoring and human-in-the-loop decision making.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: VulnScan
👤 项目作者: hacksudo
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:39:46

📝 项目描述:
A powerful, containerized Web Vulnerability Scanner featuring industry-standard security tools (Nmap, Nikto, SSLScan, TestSSL). Fully packaged into a self-contained Docker deployment that sets up in seconds.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: omnistrike
👤 项目作者: shadowboykay
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:54:27

📝 项目描述:
Modular pentest framework — 195+ modules, 14k Nuclei templates, KEV/ExploitDB, Burp-lite proxy, Flask UI, SARIF/CI, Termux-native

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Beacon

📦 项目名称: adaptix-graph-c2
👤 项目作者: stillbigjosh
🛠 开发语言: C++
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:06:23

📝 项目描述:
Cloud dead-drop C2 channel plugin for Adaptix C2 v1.2.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: PawXssScanner
👤 项目作者: Rushikesh362
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:00:30

📝 项目描述:
Fast reflected-XSS scanner with adaptive WAF-bypass engine

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Simple-Vulnerability-
👤 项目作者: asinshaik274-dev
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 13:00:42

📝 项目描述:
A Simple Vulnerability Scanner is a cybersecurity application that scans a system or website for common security weaknesses. It checks for issues such as open ports, weak configurations, outdated software indicators, and common web vulnerabilities, then generates a basic report with the detected risks and recommendations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: simple-vulnerability-scanner
👤 项目作者: asinshaik274-dev
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 12:57:53

📝 项目描述:
A Simple Vulnerability Scanner is a cybersecurity application that scans a system or website for common security weaknesses. It checks for issues such as open ports, weak configurations, outdated software indicators, and common web vulnerabilities, then generates a basic report with the detected risks and recommendations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: xss-penetration-testing
👤 项目作者: TEJASWANIANIMIREDDY
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 12:32:19

📝 项目描述:
XSS vulnerability testing guide and findings from DVWA and PortSwigger labs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #DOM

📦 项目名称: xsshunter-express
👤 项目作者: man715
🛠 开发语言: SCSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:58:53

📝 项目描述:
Self-hosted XSS Hunter Express - collect and manage XSS payloads

🔗 点击访问项目地址