Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

API安全测试

用于评估REST、SOAP和GraphQL API安全性的工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k4天前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k1天前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k17小时56分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8844个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k20天前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
380 结果
内容在请求的语言中不可用。显示英文版本。
api-security-audit-action preview

api-security-audit-action

GitHub42crunch/api-security-audit-action

在 CI/CD 中自动化对 OpenAPI 契约执行静态 API 安全审计,运行 300+ 项针对身份验证、授权和数据约束的检查,支持最低评分门禁及 SARIF 输出。

defensive-toolsstatic-analysisvulnerability-analysis+3
377个月前
mitmproxy_rs preview

mitmproxy_rs

GitHubmitmproxy/mitmproxy_rs

用于流量拦截和重定向的 Rust 组件,支持在 macOS、Windows 和 Linux 上实现 WireGuard 设备代理与本地应用重定向。

web-proxies-interceptionmobile-app-pentestingapi-security-testing+2
4471个月前
wapiti preview

wapiti

GitHubwapiti-scanner/wapiti

使用 Python3 编写的 Web 漏洞扫描器

vulnerability-scannersweb-vulnerability-scannerspassword-attacks+11
1.9k5天前
CVE-2026-9198 preview

CVE-2026-9198

GitHubk3ystr0k3r/cve-2026-9198

针对 IBM Langflow OSS 中严重未认证 RCE 的 PoC 与检测指南,涵盖 auto_login 令牌绕过及不安全的 /validate/code Python 代码执行。

vulnerability-analysisexploitationweb-application-exploitation+2
11个月前
CVE-2025-32375-PoC preview

CVE-2025-32375-PoC

GitHubsevdakhidirova/cve-2025-32375-poc

针对 BentoML 中 CVE-2025-32375 的 Python 概念验证漏洞利用程序,可在受影响的部署上演示并验证该漏洞。

vulnerability-analysisexploitationweb-application-exploitation+3
1个月前
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

检测未认证的 MLflow webhook SSRF(CVE-2026-64849),该漏洞可访问内部或云元数据服务,并通过重定向绕过泄露响应详细信息。

vulnerability-scannersexploitationweb-application-exploitation+3
1个月前
CVE-2026-19478 preview

CVE-2026-19478

GitHubrenzi25031469/cve-2026-19478

通过非破坏性 Nuclei 模板检测 GitLab CE/EE 中的 CVE-2026-19478,该模板通过 touch 触发 GraphQL 回退字段方法调用,并在不进行破坏性调用的情况下确认存在漏洞的实例。

web-vulnerability-scannersvulnerability-analysisweb-application-exploitation+4
11个月前
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

CVE-2026-44848 的 PoC:Portainer 在 Docker 插件端点缺少授权,导致主机 RCE(GHSA-rrmm-9v76-h3p4)。仅依赖标准库的 Python 实现。

authentication-authorizationcontainer-securityvulnerability-analysis+3
11个月前
masq preview

masq

GitLabwattocyber/masq

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

reconnaissancestatic-analysisvulnerability-analysis+6
1个月前
CVE-2026-71203-PoC preview

CVE-2026-71203-PoC

GitHubnel-droid/cve-2026-71203-poc

PoC:changedetection.io 未认证 OpenAPI Schema 信息泄露(CVE-2026-71203,中危 5.3)

vulnerability-analysisexploitationapi-security-testing+4
1个月前
CVE-2026-9830 preview

CVE-2026-9830

GitHubopaxial/cve-2026-9830

CVE-2026-9830 概念验证

vulnerability-analysisexploitationweb-application-exploitation+3
5721个月前
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

针对 CVE-2026-73678 的 PoC 漏洞利用:通过攻击者提供的 LLM 密钥及无沙箱的 scratchpad 执行,在 MindsDB Cowork 中实现未认证 RCE,以运行操作系统命令。

vulnerability-analysisexploitationweb-application-exploitation+4
1个月前
CVE-2026-54356 preview

CVE-2026-54356

GitHubkovachvl/cve-2026-54356

针对 CVE-2026-54356 的概念验证漏洞利用与安全公告,该漏洞是 Budibase 的一个授权缺失缺陷,可让低权限用户使用存储的 AWS 凭证生成 S3 预签名上传 URL。

vulnerability-analysisexploitationweb-application-exploitation+3
1个月前
ActBench preview

ActBench

GitHubzjuicsr/actbench

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

api-security-testingsecurity-virtualizationai-security+1
24天前
CVE-2026-9198 preview

CVE-2026-9198

GitHubcuteecat/cve-2026-9198

CVE-2026-9198利用代码

vulnerability-analysisexploitationweb-application-exploitation+3
1个月前
HTB-TwoMillion-machine preview

HTB-TwoMillion-machine

GitHubabedallarawashdeh/htb-twomillion-machine

Hack The Box TwoMillion 靶机解析 — JWT/邀请码绕过、IDOR、命令注入以及 CVE-2023-0386 权限提升。

privilege-escalationweb-application-exploitationapi-security-testing+4
1个月前
ragflow-audit preview

ragflow-audit

GitHubqianlijaingshan/ragflow-audit

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

vulnerability-scannersvulnerability-analysisexploitation+4
11个月前
CVE-2026-41473-CyberPanel-AI-Scanner-Unauth preview

CVE-2026-41473-CyberPanel-AI-Scanner-Unauth

GitHubpenteraio/cve-2026-41473-cyberpanel-ai-scanner-unauth

Nuclei 检测模板,用于 CVE-2026-41473,该漏洞是 CyberPanel AI Scanner 2.4.4 之前版本中未认证的读写 API 访问缺陷。使用两个 HTTP 探针确认缺少身份验证。

vulnerability-scannersweb-vulnerability-scannersvulnerability-analysis+3
3个月前
上一页1234…22下一页