Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

API安全测试

用于评估REST、SOAP和GraphQL API安全性的工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k4天前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k1天前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k17小时51分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8844个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k20天前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
380 结果
内容在请求的语言中不可用。显示英文版本。
jenkinsci__perfecto-plugin_CVE-2020-2261_1-17 preview

jenkinsci__perfecto-plugin_CVE-2020-2261_1-17

GitHubshoucheng3/jenkinsci__perfecto-plugin_cve-2020-2261_1-17

用于通过Perfecto云进行自动化移动应用测试的Jenkins插件,在CI/CD流水线中管理安全隧道连接和应用上传。

mobile-app-pentestingapi-security-testingcloud-security+1
1年前
Burp_CVE-2025-31324 preview

Burp_CVE-2025-31324

GitHubblueowl-overlord/burp_cve-2025-31324

基于Python的Burp Suite扩展,旨在检测CVE-2025-31324的存在。

vulnerability-scannersexploitationweb-application-exploitation+3
1年前
CVE-2023-23752 preview

CVE-2023-23752

GitHubaureum01/cve-2023-23752

一个利用Joomla! API 4.0 - 4.2.7漏洞端点的Bash自动化工具。

vulnerability-analysisexploitationweb-application-exploitation+3
2年前
CVE-2023-6289 preview

CVE-2023-6289

GitHubrandomrobbiebf/cve-2023-6289

Swift Performance Lite <= 2.3.6.14 - 缺少授权导致未认证的设置导出

vulnerability-analysisexploitationapi-security-testing+3
2年前
RISE-Ultimate_Project_Manager_e_CRM preview

RISE-Ultimate_Project_Manager_e_CRM

GitHubl4zyfox/rise-ultimate_project_manager_e_crm

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

reconnaissancevulnerability-analysisweb-application-exploitation+3
1年前
Detect_polyfill_CVE-2024-38537- preview

Detect_polyfill_CVE-2024-38537-

GitHubhavoc10-sw/detect_polyfill_cve-2024-38537-

这是一个 Python 脚本,用于检查指定 Web 应用的内容安全策略(CSP)标头中是否存在 polyfill.io 域名。

vulnerability-scannersapi-security-testingconfiguration-auditing+2
2年前
suds preview

suds

GitHubosirium/suds

克隆自 suds 0.4 + suds-0.4-CVE-2013-2217.patch

vulnerability-analysisscripting-automationapi-security-testing+3
8年前
CodePath_Week_7-8 preview

CodePath_Week_7-8

GitHubpalmtreeforest/codepath_week_7-8

CodePath 第7和第8周作业:CVE-2017-14719、CVE-2019-9787 及通过 REST API 进行的未认证页面/文章内容修改

vulnerability-analysisexploitationweb-application-exploitation+3
7年前
square__retrofit_CVE-2018-1000850_2-4-0 preview

square__retrofit_CVE-2018-1000850_2-4-0

GitHubshoucheng3/square__retrofit_cve-2018-1000850_2-4-0

类型安全的 Android 和 Java HTTP 客户端库,支持通过注解配置请求和转换器来实现 REST API 通信。

general-purpose-utilitiesapi-security-testing
1年前
SpringCloud preview

SpringCloud

GitHubcorgizz/springcloud

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

vulnerability-scannersexploitationapi-security-testing+3
4年前
Retrofit-1 preview

Retrofit-1

GitHubepicosy/retrofit-1

面向Android和Java的类型安全HTTP客户端,支持基于注解的API绑定、转换器,并与OkHttp集成进行网络通信。

general-purpose-utilitiesvulnerability-analysisapi-security-testing
2年前
bugbounty-lab101 preview

bugbounty-lab101

GitHubdevcop95/bugbounty-lab101

面向HackerOne研究人员的完整漏洞赏金工作区。包含范围强制执行、自动化侦察/漏洞流水线(400+工具)、报告模板、CVE/CWE监视列表,以及本地VM练习实验室。专为有纪律、合乎道德的狩猎而构建。

reconnaissancevulnerability-scannersweb-vulnerability-scanners+8
4111个月前
reSolver preview

reSolver

GitHubtheqmaks/resolver

该扩展将流行的 CAPTCHA 解决方案服务集成到 BurpSuite 中,无需人工干预即可处理不同类型的 CAPTCHA。

scripting-automationweb-application-exploitationapi-security-testing+5
147个月前
bifrost preview

bifrost

GitHubbifrost-proxy/bifrost

High-performance HTTP/HTTPS/SOCKS5 MITM proxy in Rust with TLS interception, rule-based request rewriting, traffic capture, breakpoints, script…

packet-sniffing-analysisweb-proxies-interceptionreverse-engineering+6
14116天前
akca preview

akca

GitHubakha-security/akca

面向证据的 Go 语言 DAST 扫描器,可爬取 Web 应用和 API,然后运行自适应 SQLi、XSS、RCE、SSRF 和认证检查,并提供可重放的证明。

defensive-toolsreconnaissancevulnerability-scanners+9
1772天前
XXERipper preview

XXERipper

GitHubkamalx06/xxeripper

黑盒XXE扫描器,通过统计基线、解析器指纹识别和OOB确认检测带内、基于错误和盲注带外注入,并支持SARIF输出。

reconnaissancevulnerability-scannersweb-vulnerability-scanners+9
4天前
reburp preview

reburp

GitHubforefy/reburp

一个将完整的 Montoya API 暴露为本地 REST API 的 Burp Suite 扩展,并带有 Swagger UI

vulnerability-scannersweb-proxies-interceptionscripting-automation+7
1037天前
HTTP3-Adapter preview

HTTP3-Adapter

GitHubt0xodile-swig/http3-adapter

Burp Suite 扩展,用于拦截请求并通过 HTTP/3 发送,再将响应转换回 Burp,支持 kettled 请求和 HTTP/3 能力检测。

web-proxies-interceptionapi-security-testingweb-security+3
13天前
上一页1…19202122下一页