Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
API 安全 | Kitploit
分类

API 安全

API 测试、模糊测试、模式验证、身份验证测试和网关安全工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k1天前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k11小时18分前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k13小时58分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8843个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k9小时14分前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
448 结果
aws__aws-sdk-java_CVE-2022-31159_1-12-2600 preview

aws__aws-sdk-java_CVE-2022-31159_1-12-2600

GitHubshoucheng3/aws__aws-sdk-java_cve-2022-31159_1-12-2600

用于集成亚马逊云服务的Java SDK,提供对S3、DynamoDB、EC2等服务的安全API访问,并内置身份验证、加密和IAM支持。

authentication-authorizationcloud-infrastructure-securityencryption-decryption-tools+3
1年前
CVE-2025-30144 preview

CVE-2025-30144

GitHubtibrn/cve-2025-30144

Proof-of-concept for CVE-2025-30144: fast-jwt 库中的 JWT 签发者校验绕过漏洞,允许攻击者利用基于数组的 iss 声明伪造令牌。

vulnerability-analysisexploitationweb-application-exploitation+3
1年前
SwaggerUI-CVE-2016-1000229 preview

SwaggerUI-CVE-2016-1000229

GitHubbarteeees/swaggerui-cve-2016-1000229

CVE-2016-1000229

vulnerability-analysisexploitationweb-security+2
11个月前
jenkinsci__docker-commons-plugin_CVE-2022-20617_1-17 preview

jenkinsci__docker-commons-plugin_CVE-2022-20617_1-17

GitHubshoucheng3/jenkinsci__docker-commons-plugin_cve-2022-20617_1-17

Jenkins 插件,为 Docker 相关的 CI/CD 插件提供共享 API,用于 Docker 凭据管理、注册表认证、守护进程配置以及镜像指纹识别。

authentication-authorizationcloud-infrastructure-securitycontainer-security+3
1年前
spring-cloud__spring-cloud-config_CVE-2020-5405_2-1-6-RELEASE preview

spring-cloud__spring-cloud-config_CVE-2020-5405_2-1-6-RELEASE

GitHubshoucheng3/spring-cloud__spring-cloud-config_cve-2020-5405_2-1-6-release

分布式系统的集中配置服务器,提供HTTP API、属性加密/解密,并支持Git、Vault、JDBC和本地文件系统后端。

authentication-authorizationencryption-decryption-toolsconfiguration-auditing+3
1年前
hapifhir__org_hl7_fhir_core_CVE-2023-28465_5-6-1055 preview

hapifhir__org_hl7_fhir_core_CVE-2023-28465_5-6-1055

GitHubshoucheng3/hapifhir__org_hl7_fhir_core_cve-2023-28465_5-6-1055

FHIR规范的Java核心库,包含验证器、版本转换器以及R2到R5的对象模型,用于HAPI服务器和HL7工具。

static-analysisvulnerability-analysiscode-analysis+3
1年前
fabric8io__kubernetes-client_CVE-2021-4178_5-0-2 preview

fabric8io__kubernetes-client_CVE-2021-4178_5-0-2

GitHubshoucheng3/fabric8io__kubernetes-client_cve-2021-4178_5-0-2

Java 客户端,提供流畅的 DSL 访问 Kubernetes 和 OpenShift REST API,用于管理云原生基础设施、Pod、服务及配置,并支持身份验证和 TLS。

authentication-authorizationcloud-infrastructure-securitycontainer-security+3
1年前
CVE-2018-25031 preview

CVE-2018-25031

GitHublucasrenaa/cve-2018-25031

基于Python的概念验证脚本,演示Swagger UI中的CVE-2018-25031 XSS漏洞,使用Selenium在多个端点上进行自动化检测。

vulnerability-analysisexploitationweb-application-exploitation+3
2年前
apache__nifi_CVE-2022-33140_1-16-22 preview

apache__nifi_CVE-2022-33140_1-16-22

GitHubshoucheng3/apache__nifi_cve-2022-33140_1-16-22

自动化数据流处理与分发系统,具备安全配置、来源追踪及可扩展的插件架构,适用于网络安全、可观测性和事件流管道。

authentication-authorizationencryption-decryption-toolsdata-exfiltration+4
1年前
suds preview

suds

GitHubosirium/suds

克隆自 suds 0.4 + suds-0.4-CVE-2013-2217.patch

vulnerability-analysisscripting-automationapi-security-testing+3
8年前
cloudfoundry_uaa preview

cloudfoundry_uaa

GitHubshanika04/cloudfoundry_uaa

CVE-2016-4468

authentication-authorizationcloud-infrastructure-securitycloud-security+3
5年前
kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed preview

kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed

GitHubshoucheng3/kubernetes-client__java_cve-2020-8570_client-java-parent-9_0_2_fixed

Java 客户端库,用于与 Kubernetes API 交互,支持以编程方式管理集群、Pod、部署及其他资源,并提供身份验证、Watch、Exec 和端口转发操作。

authentication-authorizationcloud-infrastructure-securitygeneral-purpose-utilities+3
9个月前
apache__camel_CVE-2018-8041_2-20-3 preview

apache__camel_CVE-2018-8041_2-20-3

GitHubshoucheng3/apache__camel_cve-2018-8041_2-20-3

开源集成框架,用于通过领域特定语言(Java、XML、YAML)定义路由和中介规则,以连接各种消费或产生数据的系统。

cloud-securitydevsecopsapi-security
10个月前
hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final preview

hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final

GitHubshoucheng3/hibernate__hibernate-validator_cve-2019-10219_6-0-17-final

Bean Validation 2.0(JSR-380)的参考实现,提供基于注解驱动的元数据模型和API,用于JavaBean与方法验证,并支持XML描述符。

static-analysisvulnerability-analysiscode-analysis+2
1年前
pigeon preview

pigeon

GitHubpigeonlabshq/pigeon

为AI代理强制执行最小权限委派,使用经过签名且限定范围的凭据。为子代理授予狭窄的能力和资源,在执行前验证操作,并防止权限提升。

authentication-authorizationcloud-securitydevsecops+3
73天前
ephemora-cell preview

ephemora-cell

GitHubmichaels1011/ephemora-cell

基于能力的 WASM 运行时,用于执行不受信任的 AI 生成代码,并强制执行 CPU、内存、时间、I/O 和文件系统限制。提供亚毫秒级热执行、签名执行记录,以及用于集成的 MCP 服务器。

container-securitydynamic-analysis-sandboxingsecurity-virtualization+4
115天前
CVE-2026-0915-json-Patch.-V2.0 preview

CVE-2026-0915-json-Patch.-V2.0

GitHubterra-nova83/cve-2026-0915-json-patch.-v2.0

为 CVE-2026-0915 提供安全补丁,添加严格的 JSON 模式验证、输入清理和速率限制,以防止 Node.js 应用程序中的注入和 DoS 攻击。

vulnerability-analysisweb-securitydevsecops+1
6个月前
ingress-nginx preview
Archived

ingress-nginx

GitHubkubernetes/ingress-nginx

Ingress NGINX Controller for Kubernetes

cloud-infrastructure-securitygeneral-purpose-utilitiesnetwork-security+3
19.5k5个月前
上一页1…232425下一页