GitHub 红队武器库🚨
14.1K subscribers
25 photos
8 videos
26.1K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: SvgValidator
👤 项目作者: interactivetools-com
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 04:49:59

📝 项目描述:
Rejects uploaded SVG files that could run script, load an outside resource, or hang a renderer. Matches what browsers allow for SVG in an <img> tag, streams the file once at about 100 MB/s, and never rewrites it.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-90782-s2opc-status-clobber
👤 项目作者: HarshRajSinghania
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 05:42:31

📝 项目描述:
Standalone PoC for CVE-2026-90782: status-clobbering NULL dereference in S2OPC alloc_notification_message_items() (DataChange fails, Event succeeds)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-85706
👤 项目作者: gabrielunknown
🛠 开发语言: Perl
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 05:14:39

📝 项目描述:
CVE-2026-85706 — GitLab Unauthenticated Arbitrary File Read exploit PoC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: DOM-XSS-in-Swagger-UI
👤 项目作者: TBWLE22
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 05:48:10

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: astra-security-scanner
👤 项目作者: friendlyhacker-py
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 05:13:26

📝 项目描述:
AI-assisted vulnerability scanner that normalizes technology versions, discovers NVD CPEs, and enumerates associated CVEs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XXE #POC #CVE

📦 项目名称: spring-cloud-alibaba-nacos-xml-xxe
👤 项目作者: Sky-JD
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 04:38:04

📝 项目描述:
Evidence-based disclosure and safe local reproducer for the Nacos XML external entity issue in Spring Cloud Alibaba

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: CyberVulnLab
👤 项目作者: msiuser47
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 06:05:14

📝 项目描述:
Deliberately vulnerable Flask app for learning web security , SQL Injection, Stored XSS, and IDOR with hands-on labs, attack walkthroughs, and side-by-side fixes. For beginners & students.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #POC

📦 项目名称: jenkins-security-poc
👤 项目作者: sumitroyopstree
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 07:48:13

📝 项目描述:
Jenkins poc for node js and pm2

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #漏洞

📦 项目名称: xss
👤 项目作者: chen0222-tech
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 07:40:24

📝 项目描述:
新手关于xss漏洞的靶场笔记

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader #Inject #免杀 #AV

📦 项目名称: rust-loader
👤 项目作者: guaidao2
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 03:15:52

📝 项目描述:
简单的红队shellcode加载器

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: oxclub-vuln-scanner
👤 项目作者: OxClub
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 09:00:56

📝 项目描述:
OxClub Vulnerability Scanner A cross-platform desktop GUI for web application security testing, powered by OWASP ZAP.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-72898
👤 项目作者: 34zY
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 09:59:16

📝 项目描述:
CVE-2026-72898 exploit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghost-hoock
👤 项目作者: genksome
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 09:37:16

📝 项目描述:
GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Buster
👤 项目作者: ismailsanan
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 09:47:57

📝 项目描述:
Burp Suite extension, bringing recursive directory, vhost, DNS directly into Burp Suite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-52910-poc
👤 项目作者: yolkfull
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 10:21:32

📝 项目描述:
POC of cve-2026-52910

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: -
👤 项目作者: wwwwwxysy
🛠 开发语言: Shell
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 09:36:24

📝 项目描述:
渗透测试skill

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: image-vuln-scanner
👤 项目作者: ozeranskii
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 11:06:11

📝 项目描述:
A CLI tool for scanning Docker images for vulnerabilities using Trivy and Grype.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-
👤 项目作者: Shirouuu
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 11:51:26

📝 项目描述:
PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git objects. Educational use only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: web-vulnerability-scanner
👤 项目作者: rayhanhb
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 11:41:18

📝 项目描述:
Simple Web Vulnerability Scanner for detecting SQL Injection and Reflected XSS using Python and Flask.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: BurpSuite-Korean-Patch
👤 项目作者: naroSEC
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 11:46:06

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Editorial-TJNULL-OSCP-
👤 项目作者: R3fr4kt
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 11:23:39

📝 项目描述:
This walkthrough covers the complete penetration testing lifecycle: * **Initial Access:** Identifying a Server-Side Request Forgery (SSRF) flaw in a file upload feature, fuzzing internal ports via Burp Suite Intruder, and extracting `dev` account credentials from an unauthenticated API endpoint. * **Lateral Movement:** Performing Git repository for

🔗 点击访问项目地址