Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Payload 开发 | Kitploit
分类

Payload 开发

自定义 payload 制作、混淆、AV 规避和交付机制工具。

最新相关性最受欢迎最近更新
3295 结果
内容在请求的语言中不可用。显示英文版本。
CVE-2024-56426 preview

CVE-2024-56426

GitHubxcracker000/cve-2024-56426

适用于 Exynos 9830 bootROM 的漏洞利用工具包,可为三星 SM-G985F 设备提供签名启动绕过、自定义密钥注入和内存转储载荷。

android-securityembedded-systems-securityexploitation+7
1
6天前
watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 preview

watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-preauth-rce-cve-2026-8452

针对 Citrix NetScaler CVE-2026-8452 的概念验证(PoC)漏洞利用程序,通过构建 shellcode 并经由已部署的 webshell 执行命令,验证未经身份验证的远程代码执行(RCE)漏洞。

vulnerability-analysisexploitationweb-application-exploitation+3
86天前
CVE-RUBY preview

CVE-RUBY

GitHubhorkimhab/cve-ruby

Ruby 4.0 通用 RCE 反序列化 Gadget 链 - 草稿或待办

vulnerability-analysisexploitationweb-application-exploitation+3
5天前
CVE-2026-31816 preview

CVE-2026-31816

GitHubk3ystr0k3r/cve-2026-31816

针对 Budibase 严重认证绕过漏洞的 PoC 漏洞利用:未锚定的 webhook 正则允许攻击者追加 ?/webhooks/trigger,访问受保护的 API,并串联插件上传实现 RCE。

authentication-authorizationexploitationweb-application-exploitation+3
6天前
ELFLoader preview

ELFLoader

GitHubtrustedsec/elfloader

完全在内存中加载并运行 ELF 对象,适用于 x86_64/x86 Linux 系统,在运行时解析 libc 符号,以实现隐蔽的后渗透命令执行。

post-exploitationpenetration-testingutilities-frameworks+2
3434年前
cve-2026-43499-m3q-azf1 preview

cve-2026-43499-m3q-azf1

GitHubbugel/cve-2026-43499-m3q-azf1

此软件包并非完整的 root 提权方案。它将 SELinux 切换为 Permissive 模式,并将回收(reclaim)状态保持足够长的时间以供后续利用。此处并未实现主机的 `uid=0`。

android-securityprivilege-escalationreconnaissance+4
27天前
SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit preview

SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit

GitHubomribaso/sccm-cve-2026-47301-remote-code-execution-exploit

针对 Microsoft Configuration Manager (SCCM) 的概念验证漏洞利用链 (CVE-2026-47301),结合了失效的访问控制、CAB 任意写入路径遍历、证书验证绕过和 DLL 劫持,以实现 SYSTEM 级代码执行。

privilege-escalationreconnaissanceexploitation+3
127天前
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

可配置的 Python PoC,针对 CVE-2026-54433——Roundcube 纯文本邮件渲染器中的存储型 XSS 漏洞。可生成精心构造的 .eml 文件,通过 SMTP 发送,并在 Docker 实验室中验证影响。

vulnerability-analysisexploitationweb-application-exploitation+6
6天前
CVE-2026-33017 preview

CVE-2026-33017

GitHublxxexxbxx/cve-2026-33017

Langflow <=1.8.1 中未认证 RCE 的 PoC 漏洞利用,包含源码级根因分析、AST 感知的反弹 shell 载荷、Docker 实验环境、补丁差异和检测规则。

vulnerability-analysisexploitationweb-application-exploitation+3
16天前
CVE-2026-45034 preview

CVE-2026-45034

GitHubsangsenimanwartefak/cve-2026-45034

针对 PHPSpreadsheet 的 phar:// 反序列化漏洞的 PoC 漏洞利用程序,绕过 prohibitWrappers 以在易受攻击的 PHP 应用上实现远程代码执行。

vulnerability-analysisexploitationweb-application-exploitation+1
2个月前
chyrp-lite-rce-poc preview

chyrp-lite-rce-poc

GitHubiltosec/chyrp-lite-rce-poc

CVE-2026-53767 + CVE-2026-53768 - Chyrp Lite ≤ 2026.01 中通过 uploads_path 黑名单绕过和缺失的扩展名验证实现的认证 RCE

vulnerability-analysisexploitationweb-application-exploitation+4
2个月前
CVE-2026-25938-FUXA-Unauthenticated-RCE preview

CVE-2026-25938-FUXA-Unauthenticated-RCE

GitHubjudgedbykira/cve-2026-25938-fuxa-unauthenticated-rce

关于在 FUXA 上利用 CVE-2026-25938 未认证 RCE 漏洞的说明与 PoC

iot-securityvulnerability-analysisexploitation+6
17天前
cve-2026-43499-app.so preview

cve-2026-43499-app.so

GitHubpimpamebanihah/cve-2026-43499-app.so

用于利用特定 CVE 的概念验证共享库,演示其影响并验证受影响应用部署中的暴露风险。

vulnerability-analysisexploitationpayload-development
7天前
Aether-C2-Framework preview

Aether-C2-Framework

GitHubgmh5225/aether-c2-framework

🛠️ Explore custom C2 TTPs with Aether-C2-Framework, focusing on lightweight Rust implants and stealthy transport stacks to reduce forensic…

post-exploitationcommand-and-controleducation+2
7个月前
etaHEN preview

etaHEN

GitHubetahen/etahen

PS5 自制程序启用器 payload,提供后利用功能:自定义插件/payload 加载、未签名 fself/fpkg 支持、调试设置、FTP 服务器及直接安装包安装器。

privilege-escalationexploitationpost-exploitation+3
6503个月前
CVE-2026-73034-PoC preview

CVE-2026-73034-PoC

GitHubboreas37/cve-2026-73034-poc

CVE-2026-73034 — DB-GPT v0.8.1 未授权路径遍历 → 通过 user-id 请求头以 root 身份任意文件写入。已验证 + 修复 diff

vulnerability-analysisexploitationweb-application-exploitation+3
18天前
CVE-2026-59827 preview

CVE-2026-59827

GitHubgutierre0x80/cve-2026-59827

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code…

payload-generationvulnerability-analysisexploitation+3
18天前
CVE-2017-9805-Exploit preview

CVE-2017-9805-Exploit

GitHubagent3137/cve-2017-9805-exploit

CVE-2017-9805-Exploit

vulnerability-analysisexploitationweb-application-exploitation+2
15年前
上一页123…184下一页