GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
22.1K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: SentinelScan
👤 项目作者: gutddts
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:08

📝 项目描述:
🔍 全栈漏洞扫描管理平台 — React + FastAPI,支持端口扫描/HTTP头检测/SSL验证/漏洞检测,可视化仪表盘与PDF报告

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: drupal-openai-provider-ssrf-cve-2026-13233
👤 项目作者: KuniNogu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:42:22

📝 项目描述:
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #漏洞 #EXP #POC

📦 项目名称: fastjsonRCE-66-83
👤 项目作者: vv4ke
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:56:46

📝 项目描述:
Fastjson 1.2.66 ~ 1.2.83 版本中,`checkAutoType` 方法在处理 `@JSONType` 注解时存在缺陷。通过构造特殊的 `@type` 值,可以绕过安全检查,利用 `LaunchedURLClassLoader` 从远程加载恶意类并执行。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2025-64512
👤 项目作者: BardLaudian
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:08:37

📝 项目描述:
CLI wrapper around the official PoC for CVE-2025-64512 — pdfminer.six insecure pickle deserialization via crafted PDF (RCE)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #文件上传 #漏洞

📦 项目名称: Class03-File-Upload-Security
👤 项目作者: fankfc
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:25:59

📝 项目描述:
Flask 文件上传功能实现与安全加固 — 扩展名白名单、PIL 内容校验、UUID 重命名、速率限制

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: IIT-Jammu-Final-Project
👤 项目作者: Krishna-The-Developer
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:48:50

📝 项目描述:
VulnScan is a multi-threaded network vulnerability scanner built in Python. It scans common or full port ranges (1–65535), detects open ports, applies rule-based security checks, calculates risk scores, and generates detailed HTML reports. Designed with a Tkinter GUI for educational and academic cybersecurity projects.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin

📦 项目名称: burpaderp
👤 项目作者: MKlolbullen
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:20:06

📝 项目描述:
Burp plugin for bug bounty hunters primarily.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: Fastjson-1.2.83-vuln
👤 项目作者: valleyxht
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 11:07:17

📝 项目描述:
Fastjson1.2.83漏洞利用链条拆解

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-9973-exploit
👤 项目作者: jaf0rk
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 11:57:43

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-9198_exploit
👤 项目作者: 0xdak
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 11:15:28

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: CyberShield-Web-Analyzer
👤 项目作者: waniaazam000-cpu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 11:57:58

📝 项目描述:
CyberShield Web Analyzer is a Python-based web vulnerability scanner that performs basic security assessments of websites. It detects common security issues, calculates a risk score, and generates a downloadable security report through an interactive Streamlit dashboard.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: fastjson-1.2.83-gadget-rce
👤 项目作者: DmTomHL
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 82
📅 更新时间: 2026-07-21 03:17:15

📝 项目描述:
Fastjson 1.2.68 ~ 1.2.83 RCE,jdk8、17、21和25全版本,支持批量urls进行poc验证。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-53913
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 12:48:08

📝 项目描述:
PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required roles/permissions the token is never verified, so any forged/garbage bearer token bypasses authentication (unauthenticated RCE). Fixed in 4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-27654-PoC
👤 项目作者: Debajyoti0-0
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 12:39:40

📝 项目描述:
Proof-of-Concept and technical analysis for CVE-2026-27654, a heap-based buffer overflow vulnerability in the NGINX HTTP WebDAV module, including root cause analysis, reproduction, and mitigation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: xss-impact-poc
👤 项目作者: bnjmzzn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 12:54:41

📝 项目描述:
My personal collection of safe XSS impact PoC scripts

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: wmg-xss-stored-cyberrange
👤 项目作者: IBsandeshCT
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 12:26:31

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-api-security-extension
👤 项目作者: Lucifer0031J
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 12:49:21

📝 项目描述:
qwertghj

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: cyberdercy-portfolio
👤 项目作者: S5eader
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 12:53:00

📝 项目描述:
Personal cybersecurity portfolio showcasing projects, skills, certifications and DercyScan vulnerability scanner.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: ExploitMind
👤 项目作者: Cazo-Net
🛠 开发语言: PowerShell
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 13:53:13

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Scannar
👤 项目作者: MohdAbushahma
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 13:43:09

📝 项目描述:
Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Domi-Reversi---Sensitive-Data-Anonymizer---Burp-Extension
👤 项目作者: Darnxca
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 14:04:51

📝 项目描述:
无描述

🔗 点击访问项目地址