GitHub 红队武器库🚨
14K subscribers
25 photos
8 videos
25.9K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: dolibarr-24.0.1-xss
👤 项目作者: maidou193-dot
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 15:51:01

📝 项目描述:
Security advisory: stored XSS via HTML-entity bypass of the dolPrintHTML javascript: filter in Dolibarr <= 24.0.1 (CWE-79, CVSS 8.0)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: hackcar-writeup
👤 项目作者: iapetus12
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 15:38:01

📝 项目描述:
Writeup: Hackcar - DockerLabs (Node.js Inspector RCE + CVE-2025-55182 React2Shell)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-41096-PoC
👤 项目作者: ZeroDayEvil
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 16:46:41

📝 项目描述:
🛡️ Official AI Security Tool module for CVE-2026-41096 (Windows DNSAPI.dll Heap Overflow / DNS-Mayhem Deep Dive Analysis & Audit Module).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-85706
👤 项目作者: mhtsec
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 16:42:16

📝 项目描述:
GitLab CE/EE unauthenticated arbitrary file read (CVE-2026-85706) - PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: simple-python-scanner
👤 项目作者: tziatziospanagioths
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 16:53:41

📝 项目描述:
python web vulnerability scanner built

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnscanner
👤 项目作者: judejacob1027-hack
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 16:27:48

📝 项目描述:
🔐 Python Vulnerability Scanner A Python-based network vulnerability scanner built with Nmap for authorized security testing, CTFs, and lab environments.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2026-85612
👤 项目作者: hotplugin0x01
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 16:21:59

📝 项目描述:
OpenPanel Unauthenticated Server-Side Request Forgery (SSRF)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: Nuclei-And-Inside
👤 项目作者: lhilbert
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 17:07:12

📝 项目描述:
Repository to support co-development of microscopy image analysis of nuclei as well as objects and structures within them.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-2026-79294
👤 项目作者: MGTx2
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 17:31:48

📝 项目描述:
CVE-2026-79294 — Stored XSS in Moonshot AI Kimi's HTML artifact Preview, delivered through the public Share view, leading to session token exfiltration and demonstrated account takeover. Responsible disclosure advisory.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-39987_POC
👤 项目作者: julichaan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 18:30:35

📝 项目描述:
Marimo WS Preauth RCE

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: spectre-ssrf-lab
👤 项目作者: het-P301204
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 19:02:15

📝 项目描述:
Self-contained SSRF research lab — 7 services, 13 scenarios, 6 bypass techniques, detection rules, and an animated dashboard. All on 127.0.0.1.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Url_shortener
👤 项目作者: VinayKrishna-7
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 18:07:13

📝 项目描述:
Production-grade full-stack URL shortener SaaS with real-time analytics, dynamic QR codes, custom aliases, SSRF security guard, rate limiting, and Next.js 15 App Router.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: echidna
👤 项目作者: imankhayam
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 19:40:31

📝 项目描述:
lightweight Linux command-and-control (C2) framework

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: repeater-tab-auto-namer
👤 项目作者: sdushantha
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 20:02:16

📝 项目描述:
Burp extension that auto-names Repeater tabs to "{METHOD} {PATH}"

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: crisp-worker-rig-investigation
👤 项目作者: rwillmann
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 19:35:45

📝 项目描述:
Investigation note, IOCs, YARA rules and samples for crisp-worker-rig, a self-healing WordPress backdoor with Ethereum (EtherHiding) C2

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-42978-PoC-Research
👤 项目作者: SyntaxMethod
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 20:53:50

📝 项目描述:
CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module for AI Security Tool.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-85706-PoC
👤 项目作者: solivaquaant
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 19:48:42

📝 项目描述:
PoC for CVE-2026-85706: GitLab CE/EE unauthenticated arbitrary local file read

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: ACRA-Burp-Authorization-Auditor
👤 项目作者: HamzaZulfeqar
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 20:43:48

📝 项目描述:
ACRA is a Burp Suite extension for advanced authorization security auditing, correlating URI, identity, role, tenant, resource ownership, workflow state, policy, and evidence to identify access-control weaknesses.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: scanner
👤 项目作者: ykocaman
🛠 开发语言: Go
Star数量: 5 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 21:59:55

📝 项目描述:
A Go-based vulnerability scanner for Linux hosts that checks installed packages against Red Hat, Debian, Ubuntu, and Alpine CVE feeds, then reports impacted packages with version-aware matching, summary tables, and optional email/Elasticsearch output.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: ferralon-assay
👤 项目作者: ferralon-ai
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 21:50:19

📝 项目描述:
Proof infrastructure for autonomous vulnerability patching — proves in your own CI build whether a CVE is actually exploitable, at PR time.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-89013
👤 项目作者: Faceless0x7
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 22:49:48

📝 项目描述:
CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files.

🔗 点击访问项目地址