Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

API 安全

API 测试、模糊测试、模式验证、身份验证测试和网关安全工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k1天前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k17小时53分前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k20小时32分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8843个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k15小时48分前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
447 结果
Agent-Skills-Security-Standard preview

Agent-Skills-Security-Standard

GitHubowasp/agent-skills-security-standard

代理技能的安全标准,提供指南和最佳实践,以保护云和API环境中AI驱动的自主代理。

cloud-securitysupply-chain-securityeducation+3
14个月前
CVE-2024-1209 preview

CVE-2024-1209

GitHubkarlemilnikka/cve-2024-1209

通过 LearnDash 中的作业暴露敏感信息。

vulnerability-analysisinformation-gatheringweb-security+3
22年前
mcp-doorman preview

mcp-doorman

GitHubsushank05/mcp-doorman

一个轻量级 MCP,用于防范 CVE 投毒(CVE-2025-54136)、研究人员通过提示注入劫持 Claude Code/Copilot/Gemini,以及数百个零认证暴露的 MCP 服务器;该 MCP 保护的是个人开发者的笔记本电脑,而大多数 MCP 服务器实际上正是在此运行。

defensive-toolsvulnerability-scannerssecret-detection+5
6天前
kit-oauth preview

kit-oauth

GitLabkit-lang/packages/kit-oauth

OAuth 2.0 客户端库,适用于Kit应用程序,支持授权码、PKCE、客户端凭证和刷新令牌流程,内置GitHub、Google、Microsoft、Discord、Slack和GitLab的提供商预设。

authentication-authorizationutilities-frameworksauthentication+1
1个月前
mcp-stdio-shellguard preview

mcp-stdio-shellguard

GitHubstudiomeyer-io/mcp-stdio-shellguard

MCP stdio 服务器的纵深防御包:即插即用的 guardExec/guardSpawn 包装器、AST 审计 CLI、参考 MCP 服务器。修复了 Ox-Security 20 万服务器 stdio-RCE 类漏洞(LiteLLM CVE-2025-69256)。MIT…

static-analysisvulnerability-scannerscode-analysis+5
7天前
about-hmac preview

about-hmac

GitHubpassword123456/about-hmac

HMAC 实现示例与说明

cryptographyauthenticationeducation+1
22年前
CVE-2025-61777 preview

CVE-2025-61777

GitHub0x0w1z/cve-2025-61777

CVE 影响 FlagForgeCTF v2.0.0 至 v2.3.1 版本。已升级至 2.3.2 版本以修复该问题。

vulnerability-analysisexploitationweb-security+2
210个月前
CVE-2025-67923 preview

CVE-2025-67923

GitHubrandomrobbiebf/cve-2025-67923

JetEngine <= 3.7.7 — 通过 CCT REST API 的未认证存储型跨站脚本

vulnerability-analysisexploitationweb-application-exploitation+2
6个月前
CVE-2026-5724 preview

CVE-2026-5724

GitHubtibrn/cve-2026-5724

CVE-2026-5724 的概念验证漏洞利用程序,该漏洞是 Temporal 前端 gRPC 服务中的身份验证绕过漏洞,允许未经身份验证访问工作流复制数据。

vulnerability-analysisexploitationweb-security+2
4个月前
CVE-2026-25197 preview

CVE-2026-25197

GitHubmichaeladamgroberman/cve-2026-25197

CVE-2026-25197:通过 IDOR 的授权绕过 — Gardyn Home Kit (ICSA-26-055-03)

reconnaissanceiot-securityvulnerability-analysis+6
3个月前
CVE-2026-32646 preview

CVE-2026-32646

GitHubmichaeladamgroberman/cve-2026-32646

CVE-2026-32646:管理设备端点缺少身份验证 — Gardyn Home Kit(ICSA-26-055-03)

reconnaissanceiot-securityvulnerability-analysis+6
3个月前
CVE-2026-8181 preview

CVE-2026-8181

GitHubx48ps/cve-2026-8181

该漏洞允许知道有效管理员用户名的未认证攻击者在REST API请求期间通过使用基本认证头中的任何错误密码来冒充该管理员。攻击者可能滥用此缺陷在无需事先认证的情况下创建新的管理员账户。

vulnerability-analysisexploitationimpersonation-tools+3
3个月前
CVE-2026-44595 preview

CVE-2026-44595

GitHubex-cal1bur/cve-2026-44595

# CVE-2026-44595 YAMCS通过IAM API进行未授权用户枚举

authentication-authorizationvulnerability-analysisexploitation+3
3个月前
CVE-2026-35616-detector.py preview

CVE-2026-35616-detector.py

GitHubfevar54/cve-2026-35616-detector.py

CVE-2026-35616 检测器:识别存在漏洞的 FortiClient EMS 服务器(7.4.5-7.4.6)。

vulnerability-scannersvulnerability-analysisnetwork-security+2
5个月前
CVE-2025-11203-PoC preview

CVE-2025-11203-PoC

GitHublearner202649/cve-2025-11203-poc

用于个人复现相应漏洞的代码

vulnerability-analysisexploitationinformation-gathering+3
3个月前
CVE-2026-31283 preview

CVE-2026-31283

GitHubsaykino/cve-2026-31283

CVE-2026-31283的文档:Totara LMS的忘记密码API因缺少速率限制而存在电子邮件轰炸漏洞,允许未经认证的远程攻击者淹没受害者邮箱。

vulnerability-analysisweb-securitymisconfiguration+3
4个月前
CVE-2026-42154 preview

CVE-2026-42154

GitHubshadowbyte1/cve-2026-42154

CVE-2026-42154 的概念验证漏洞利用程序,该漏洞是 Prometheus Remote Read 端点中通过特制的 Snappy 压缩请求触发的拒绝服务漏洞。

vulnerability-analysisexploitationcloud-security+1
3个月前
CVE-2026-28767 preview

CVE-2026-28767

GitHubmichaeladamgroberman/cve-2026-28767

CVE-2026-28767:管理通知端点缺少身份验证 — Gardyn Home Kit(ICSA-26-055-03)

iot-securityvulnerability-analysisweb-security+3
3个月前
上一页1…181920…25下一页