Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

API安全测试

用于评估REST、SOAP和GraphQL API安全性的工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k1小时56分前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k1天前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k21小时9分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8844个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k20天前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
380 结果
内容在请求的语言中不可用。显示英文版本。
CVE-2026-34910-PoC preview

CVE-2026-34910-PoC

GitHubboreas37/cve-2026-34910-poc

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

vulnerability-analysisexploitationweb-application-exploitation+3
71个月前
CVE-2025-59528-PoC preview

CVE-2025-59528-PoC

GitHubloaxert/cve-2025-59528-poc

针对 CVE-2025-59528 的 PoC,用于在 HTB 的 Silentium 机器上实现远程代码执行。

exploitationweb-application-exploitationapi-security-testing+3
1个月前
pentest-mapper preview

pentest-mapper

GitHubportswigger/pentest-mapper

一个用于应用程序渗透测试的 Burp Suite 扩展,用于映射流程和漏洞。

vulnerability-analysisapi-security-testingweb-security+2
1222年前
api_wordlist preview

api_wordlist

GitHubchrislockard/api_wordlist

用于 Web 应用程序评估的 API 名称词表

api-security-testingweb-securityfuzzing+2
9261年前
wp2shell-Exploit-Waf-Bypass preview

wp2shell-Exploit-Waf-Bypass

GitHubm4xsec/wp2shell-exploit-waf-bypass

WordPress 预认证 RCE 漏洞利用 + 扫描器 + WAF 绕过 | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit 模块 + Docker 实验环境

web-vulnerability-scannersexploitationweb-application-exploitation+4
21个月前
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite 扩展,用于验证 OAUTHv2 和 OpenID 安全性

authentication-authorizationvulnerability-scannersapi-security-testing+6
1781年前
feroxfuzz preview

feroxfuzz

GitHubepi052/feroxfuzz

使用 Rust 构建结构感知的黑盒 HTTP 模糊测试器,具备可组合的变异器、调度器、观察器、决策器和处理器,用于自定义 Web 和 API 测试。

api-security-testingweb-securityfuzzing+1
2238个月前
poc-h2-CVE-2026-71554 preview

poc-h2-CVE-2026-71554

GitHubsunandm/poc-h2-cve-2026-71554

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

vulnerability-analysisexploitationweb-application-exploitation+4
11个月前
langflow-cors-scanner preview

langflow-cors-scanner

GitHubridhinva/langflow-cors-scanner

扫描器:CVE-2025-34291 Langflow 来源验证错误 / CORS 配置错误 — Python 检查器 (CISA KEV)

vulnerability-scannersapi-security-testingweb-security+2
1个月前
TOTPAuthenticate preview

TOTPAuthenticate

GitHubhannah-portswigger/totpauthenticate

该扩展适用于 Burp Suite Enterprise Edition,利用会话处理规则为出站请求提供 TOTP 令牌。

api-security-testingweb-securitypenetration-testing+1
92年前
poc_salesforce_lightning preview

poc_salesforce_lightning

GitHubmoniik/poc_salesforce_lightning

仅限学术用途。以访客权限攻击 Salesforce Lightning。

exploitationweb-application-exploitationapi-security-testing+4
1845年前
jsluicepp preview

jsluicepp

GitHub0x999-x/jsluicepp

jsluice++ 是一款 Burp Suite 扩展,旨在使用命令行工具 jsluice 对 JavaScript 流量进行被动和主动扫描。

reconnaissancestatic-code-analysisapi-security-testing+3
3022年前
CVE-2026-11103-GraphQL-Batching-Alias-Rate-Limit-Bypass preview

CVE-2026-11103-GraphQL-Batching-Alias-Rate-Limit-Bypass

GitHubgeorge0papasotiriou/cve-2026-11103-graphql-batching-alias-rate-limit-bypass

CVE-2026-11103 的概念验证漏洞利用,演示如何通过批处理(batching)和字段别名(field aliases)绕过 GraphQL 速率限制;包含存在漏洞的 Node.js 服务器和 Python 漏洞利用脚本。

vulnerability-analysisexploitationweb-application-exploitation+3
1个月前
API-Wordlist preview

API-Wordlist

GitHubnet-hunter121/api-wordlist

精选的 API 函数名、动词和名词词表,用于配合 Burp Suite Intruder 对 Web 应用端点进行模糊测试。

api-security-testinginformation-gatheringweb-security+3
2545年前
FlowAnalyzer preview

FlowAnalyzer

GitHubmanuelberrueta/flowanalyzer

FlowAnalyzer 是一款用于测试和分析 OAuth 2.0 流程(包括 OpenID Connect (OIDC))的工具。

authentication-authorizationapi-security-testingweb-security+5
1822年前
WuppieFuzz preview

WuppieFuzz

GitHubtno-s3/wuppiefuzz

A coverage-guided REST API fuzzer developed on top of LibAFL

vulnerability-analysisapi-security-testingweb-security+3
2177天前
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

当 UI 被禁用时,用于绕过 Azure APIM 注册的 Python 脚本,这与 CVE-2025-66390 不同,因为它不需要你在跨租户之间设置任何内容。

authentication-authorizationcloud-infrastructure-securityweb-application-exploitation+6
1个月前
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

cloud-infrastructure-securitystatic-analysiscontainer-security+8
7858天前
上一页1…345…22下一页
API安全测试 | Kitploit