Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
API安全测试 | Kitploit
分类

API安全测试

用于评估REST、SOAP和GraphQL API安全性的工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k4天前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k1天前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k16小时51分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8844个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k20天前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
380 结果
内容在请求的语言中不可用。显示英文版本。
dynast-bench preview

dynast-bench

GitHubj3ssie/dynast-bench

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

vulnerability-scannersweb-vulnerability-scannersapi-security-testing+4
126天前
React2Shell-Scanner preview

React2Shell-Scanner

GitHubwi3memake/react2shell-scanner

命令行安全评估框架,适用于 React 和 Next.js 应用程序,可分析 React Server Components 中的错误配置,支持多目标扫描、WAF 检测和代理支持。

vulnerability-scannersapi-security-testingwaf-bypass+3
319个月前
your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack preview

your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

GitHubhunt-benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

CVE-2026-68929 的概念验证漏洞利用,演示了通过公开的 shareId 对 FastGPT 微信渠道进行未认证的跨租户接管,包括渠道劫持和拒绝服务(DoS)。

vulnerability-analysisexploitationweb-application-exploitation+3
1个月前
yLog4j preview

yLog4j

GitHuby-security/ylog4j

PortSwigger Burp 插件,用于检测 Log4j(CVE-2021-44228)漏洞

vulnerability-scannersexploitationapi-security-testing+2
24年前
CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication preview

CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication

GitHubdylvie/cve-2026-30824-flowise-nvidia-nim-authentication

针对 **CVE-2026-30824** 的概念验证漏洞利用程序,这是 Flowise 中一个严重的身份验证绕过漏洞,可在无需身份验证的情况下暴露 NVIDIA NIM API 端点。

reconnaissancevulnerability-scannersexploitation+3
5个月前
CVE-2026-26012 preview

CVE-2026-26012

GitHubdiegobaelen/cve-2026-26012

CVE-2026-26012 的概念验证漏洞利用,演示了 Vaultwarden 中经过身份验证的组织集合权限绕过和密码枚举。包含一个 Python 脚本,用于复现该问题并比较集合访问差异。

vulnerability-analysisexploitationapi-security-testing+3
7个月前
Ni8mare preview

Ni8mare

GitHubcropnet/ni8mare

针对 n8n 工作流自动化实例的全面漏洞检测工具。可检测关键漏洞 CVE-2026-21858(CVSS 10.0),且不执行任何利用操作。

defensive-toolsvulnerability-scannersapi-security-testing+3
28个月前
zimaos-cve-2026-28286-arbitrary-file-write preview

zimaos-cve-2026-28286-arbitrary-file-write

GitHubrushi9/zimaos-cve-2026-28286-arbitrary-file-write

CVE-2026-28286 的 PoC 与验证工具包,该漏洞是 ZimaOS 中的任意文件写入漏洞,利用 API 配置错误将文件写入预期目录之外。

vulnerability-analysisexploitationweb-application-exploitation+3
25个月前
CVE-2026-25126 preview

CVE-2026-25126

GitHubjvr2022/cve-2026-25126

CVE-2026-25126 的概念验证,演示了通过不当的运行时验证论坛投票方向参数,在 PolarLearn 中操纵投票计数,并附有修复详情。

vulnerability-analysisexploitationweb-application-exploitation+2
18个月前
forticlient_ems_cve_2026_35616_poc.py preview

forticlient_ems_cve_2026_35616_poc.py

GitHubfevar54/forticlient_ems_cve_2026_35616_poc.py

CVE-2026-35616 的 PoC:FortiClient EMS 中的不当访问控制。

vulnerability-scannersexploitationapi-security-testing+2
5个月前
CVE-2026-35045-PoC preview

CVE-2026-35045-PoC

GitHubfilipegaudard/cve-2026-35045-poc

CVE-2026-35045 的概念验证漏洞利用程序,这是 Tandoor Recipes 中的一个对象级授权失效漏洞,演示了通过 batch_update API 端点进行未授权食谱修改。

vulnerability-analysisexploitationweb-application-exploitation+3
15个月前
CVE-2026-24134-PoC preview

CVE-2026-24134-PoC

GitHubfilipegaudard/cve-2026-24134-poc

针对 CVE-2026-24134 的概念验证漏洞利用程序,该漏洞是 StudioCMS 中的一个对象级授权失效(BOLA)漏洞,用于演示对草稿内容的未授权访问。

vulnerability-analysisexploitationweb-application-exploitation+3
8个月前
CVE-2026-30944-PoC preview

CVE-2026-30944-PoC

GitHubfilipegaudard/cve-2026-30944-poc

Python 概念验证,针对 CVE-2026-30944,利用 StudioCMS 中的 BOLA 漏洞,通过不安全的 API 令牌生成来提升权限。

privilege-escalationvulnerability-analysisexploitation+4
6个月前
gitlab-cve-2026-19478-lab preview

gitlab-cve-2026-19478-lab

GitHubdinosn/gitlab-cve-2026-19478-lab

可复现的 A/B 实验室 + 针对 GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced) 的安全 PoC

vulnerability-analysisexploitationweb-application-exploitation+4
101个月前
cve-2026-19478 preview

cve-2026-19478

GitHubn0xdaemon/cve-2026-19478

提供针对两个 GitLab GraphQL `@gl_introduced` 指令漏洞的 PoC 利用程序和根因分析:未认证方法执行与批量文档交换,并附上游补丁和实时证据。

vulnerability-analysisexploitationweb-application-exploitation+2
1个月前
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

针对 CVE-2026-19478 的 Docker 化漏洞利用实验室与脚本,这是一个严重的未认证 GitLab GraphQL 代码注入漏洞,可实现任意 Ruby 方法调用、项目删除与数据外泄。

vulnerability-analysisexploitationweb-application-exploitation+4
1个月前
Agentic-Bug-Hunter preview

Agentic-Bug-Hunter

GitHubawarexone/agentic-bug-hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

reconnaissancevulnerability-scannersweb-vulnerability-scanners+8
5.2k4天前
httptoolkit preview

httptoolkit

GitHubhttptoolkit/httptoolkit

HTTP Toolkit 是一款精美且开源的 HTTP(S) 调试、测试和构建工具,支持 Windows、Linux 和 Mac :tada: 在此处提交 issue 以提供反馈或寻求帮助。

general-purpose-utilitiesweb-proxies-interceptionapi-security-testing+1
3.6k7个月前
上一页123…22下一页