Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

漏洞利用

用于利用漏洞以获取对系统或数据的未经授权访问的工具。

最新相关性最受欢迎最近更新
23065 结果
内容在请求的语言中不可用。显示英文版本。
discover preview

discover

GitHubleebaird/discover

自定义的Bash和Python脚本,用于自动化各种渗透测试任务,包括侦察、扫描、枚举以及使用Metasploit创建恶意载荷。适用于Kali Linux和Ubuntu。

osintreconnaissancevulnerability-scanners+9
3.9k1天前
CVE-2026-43499-S26 preview

CVE-2026-43499-S26

GitHub1ndevelopment/cve-2026-43499-s26

在 Android GKI 6.12 设备上利用 CVE-2026-43499:确定性任意内核读/写、KASLR 绕过,以及通过 LD_PRELOAD 载荷获得完全 root 权限。

android-securityprivilege-escalationvulnerability-analysis+4
71天前
nxboot preview

nxboot

GitHubnikameru/nxboot

Payload injection tool for Nintendo Switch consoles vulnerable to CVE-2018-6242 ("Fusée Gelée")

embedded-systems-securityvulnerability-analysisexploitation+1
11天前
sliver preview

sliver

GitHubbishopfox/sliver

对手仿真框架

penetration-testing-frameworksexploit-frameworkspayload-generation+4
11.7k1天前
h3-cli preview

h3-cli

GitHubhorizon3ai/h3-cli

CLI tool for the Horizon3.ai API

penetration-testing-frameworksvulnerability-analysisscripting-automation+3
251天前
security-labs-pocs preview

security-labs-pocs

GitHubdatadog/security-labs-pocs

Datadog Security Labs 所引用漏洞利用程序的概念验证代码。

privilege-escalationvulnerability-analysisexploitation+4
4501天前
PAYLOAD-LISTS preview

PAYLOAD-LISTS

GitHubnu11secur1ty/payload-lists

精心策划的注入载荷集合,用于Web应用安全测试,涵盖SSTI、XXE、XSS、SSRF、SQLi、NoSQLi、LDAP、命令注入等。

payload-generationvulnerability-analysisweb-application-exploitation+3
41天前
CVE-2026-39987 preview

CVE-2026-39987

GitHubk3ystr0k3r/cve-2026-39987

Marimo 预认证 RCE 的概念验证漏洞利用。利用未认证的 /terminal/ws WebSocket 端点生成 PTY 并建立反向 shell。

vulnerability-analysisexploitationweb-application-exploitation+2
1天前
PoC-in-GitHub preview

PoC-in-GitHub

GitHubnomi-sec/poc-in-github

📡 PoC 自动从 GitHub 收集。⚠️ 小心恶意软件。

exploit-frameworksvulnerability-analysisexploitation+5
8.0k1天前
PyIris preview

PyIris

GitHubnot-sekiun/pyiris

PyIris 是一个用 Python 编写的模块化远程访问木马工具包,针对 Windows 和 Linux 系统。

payload-generationexploitationpost-exploitation+4
3251天前
Cybersec preview

Cybersec

GitHubamitr12/cybersec

面向红队和渗透测试人员的单文件HTML速查表,具有自动注入攻击者/目标变量、感知操作系统的反向Shell生成器,以及跨7个渗透测试阶段的智能复制命令按钮。

password-crackingprivilege-escalationreconnaissance+9
91天前
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms 插件单请求 RCE(通过 URL),PoC + 漏洞利用链

exploitationweb-application-exploitationweb-security+3
11天前
wasm2c-tableflip preview

wasm2c-tableflip

GitHubtrustsig-eu/wasm2c-tableflip

wasm2c 沙箱逃逸。一个不受信任的 WebAssembly 模块突破了生成的 C 沙箱,并在主机上执行任意 shell 命令。

vulnerability-analysisexploitationsecurity-virtualization+1
41天前
certighost preview

certighost

GitHubl0u7r3/certighost

CVE-2026-54121 的概念验证利用代码,经过改编和编辑,用于在受影响环境中验证该漏洞。

vulnerability-analysisexploitationpenetration-testing
1天前
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - 未认证的任意文件上传(通过伪造的上传字段配置)

vulnerability-analysisexploitationweb-application-exploitation+3
1天前
CVE-2026-61241 preview

CVE-2026-61241

GitHubgodliveanton/cve-2026-61241

Oracle OID LDAP 服务器权限管理漏洞利用

privilege-escalationexploitationnetwork-security+3
1天前
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

检测未认证的 MLflow webhook SSRF(CVE-2026-64849),该漏洞可访问内部或云元数据服务,并通过重定向绕过泄露响应详细信息。

vulnerability-scannersexploitationweb-application-exploitation+3
1天前
CVE-2021-42013_821311 preview

CVE-2021-42013_821311

GitHubandreamammano89-maker/cve-2021-42013_821311

在渗透测试期间,利用 Apache HTTP Server CVE-2021-42013 进行路径遍历和基于 CGI 的远程代码执行。

vulnerability-analysisexploitationweb-application-exploitation+1
1天前
上一页1…345…1282下一页