SploitScan 是一款强大且用户友好的工具,旨在简化已知漏洞及其利用概率的识别过程。它赋能网络安全专业人员快速识别并应用已知的测试性漏洞利用代码。对于希望加强安全措施或针对新兴威胁制定稳健检测策略的专业人士来说,该工具尤其有价值。
CVE 信息检索
获取漏洞的详细信息。
EPSS 集成
利用漏洞利用预测评分系统(EPSS)的数据检查漏洞被利用的可能性。
公开漏洞利用聚合
收集公开可用的漏洞利用数据,帮助您理解每个漏洞的上下文。
CISA KEV 集成
快速查看某个漏洞是否被列入 CISA 已知被利用漏洞(KEV)目录。
AI 驱动的风险评估
使用多种 AI 提供商(OpenAI ChatGPT、Google Gemini、Grok AI 或 DeepSeek)获取风险评估,解释潜在风险并提供缓解建议。
HackerOne 报告
查明某个漏洞是否涉及 HackerOne 漏洞赏金报告,包括基本排名和严重性详情。
补丁优先级系统
根据 CVSS、EPSS 和可用的漏洞利用信息,获得简单的补丁优先级评级。
多 CVE 支持与导出选项
同时处理多个 CVE,并将结果导出为 HTML、JSON 或 CSV 格式。
漏洞扫描器导入
从流行的漏洞扫描器(Nessus、Nexpose、OpenVAS、Docker)导入扫描结果,直接搜索已知漏洞。现在支持使用 --input-dir 进行基于目录的导入,以批量处理多个报告。
细粒度方法选择
选择具体要运行的数据检索方法(如 CISA、EPSS、HackerOne、AI 等),只获取您需要的信息。
本地 CVE 数据库更新与克隆
维护一份本地 CVE 列表 V5 仓库副本。这允许您在本地更新完整的 CVE 数据以供离线使用和搜索。
跨来源的关键词 CVE 搜索
通过关键词(例如“Apple”)在本地数据库以及 CISA 和 Nuclei 模板等远程来源中搜索 CVE。
快速模式简化输出
使用快速模式仅显示基本 CVE 信息,跳过额外查询以获得更快速的结果。
用户友好界面
享受清晰直观的界面,所有信息以易于阅读的格式呈现。

git clone https://github.com/xaitax/SploitScan.git cd sploitscan pip install -r requirements.txt
### pip```shell
pip install --user sploitscan
apt install sploitscan
### 获取 API 密钥
- **VulnCheck**:在 [VulnCheck](https://vulncheck.com/) 注册免费账户以获取您的 API 密钥。
- **OpenAI**:在 [OpenAI](https://platform.openai.com/signup/) 创建账户并获取 API 密钥。
- **Google Gemini**:在 [Google AI Studio](https://aistudio.google.com/app/apikey) 创建账户并获取 API 密钥。
- **xAI Grok**:在 [xAI](https://x.ai/api) 创建账户并获取 API 密钥。
- **DeepSeek**:在 [DeepSeek](https://platform.deepseek.com/api_keys) 创建账户并获取 API 密钥。
### 配置文件
SploitScan 默认在多个位置查找 `config.json`。它会按以下顺序加载找到的第一个有效文件:
1. **通过 `--config` 或 `-c` 传递的自定义路径**
2. **环境变量**:`SPLOITSCAN_CONFIG_PATH`
3. **本地和标准配置文件位置**:
- 当前工作目录
- `~/.sploitscan/config.json`
- `~/.config/sploitscan/config.json`
- `~/Library/Application Support/sploitscan/config.json` (macOS)
- `%APPDATA%/sploitscan/config.json` (Windows)
- `/etc/sploitscan/config.json`
> **注意**:只加载一个文件——在上述序列中找到的第一个文件。您可以将 `config.json` 放置在这些路径中的任意一个。
典型的 `config.json` 可能如下所示:```json
{
"vulncheck_api_key": "",
"openai_api_key": "",
"google_ai_api_key": "",
"grok_api_key": "",
"deepseek_api_key": ""
}
$ python .\sploitscan.py -h
███████╗██████╗ ██╗ ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗ ██╗ ██╔════╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗ ██║ ███████╗██████╔╝██║ ██║ ██║██║ ██║ ███████╗██║ ███████║██╔██╗ ██║ ╚════██║██╔═══╝ ██║ ██║ ██║██║ ██║ ╚════██║██║ ██╔══██║██║╚██╗██║ ███████║██║ ███████╗╚██████╔╝██║ ██║ ███████║╚██████╗██║ ██║██║ ╚████║ ╚══════╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝ v0.14.0 / Alexander Hagenah / @xaitax / [email protected]
usage: sploitscan.py [-h] [-e {json,csv,html}] [-t {nessus,nexpose,openvas,docker}] [--ai {openai,google,grok,deepseek}] [-k KEYWORDS [KEYWORDS ...]] [-local] [-f] [-m METHODS] [-i IMPORT_FILE] [-c CONFIG] [-d] [cve_ids ...]
SploitScan: Retrieve and display vulnerability and exploit data for specified CVE ID(s).
positional arguments: cve_ids Enter one or more CVE IDs (e.g., CVE-YYYY-NNNNN). This is optional if an import file is provided via -i.
options: -h, --help show this help message and exit -e {json,csv,html}, --export {json,csv,html} Export the results in the specified format ('json', 'csv', or 'html'). -t {nessus,nexpose,openvas,docker}, --type {nessus,nexpose,openvas,docker} Specify the type of the import file ('nessus', 'nexpose', 'openvas', or 'docker'). --ai {openai,google,grok,deepseek} Select the AI provider for risk assessment (e.g., 'openai', 'google', 'grok', or 'deepseek'). -k KEYWORDS [KEYWORDS ...], --keywords KEYWORDS [KEYWORDS ...] Search for CVEs related to specific keywords (e.g., product name). -local, --local-database Download the cvelistV5 repository into the local directory. Use the local database over online research if available. -f, --fast-mode Enable fast mode: only display basic CVE information without fetching additional exploits or data. -m METHODS, --methods METHODS Specify which methods to run, separated by commas (e.g., 'cisa,epss,hackerone,ai,prio,references'). -i IMPORT_FILE, --import-file IMPORT_FILE Path to an import file. When provided, positional CVE IDs can be omitted. The file should be a plain text list with one CVE per line. --input-dir INPUT_DIR Path to a directory containing vulnerability reports to scan for CVE IDs. -c CONFIG, --config CONFIG Path to a custom configuration file. -d, --debug Enable debug output.
### 单个 CVE 查询```bash
sploitscan CVE-2024-1709
sploitscan CVE-2024-1709 CVE-2024-21413
### 本地 CVE 数据库更新
您现在可以使用 `--local` 选项在本地更新(或初始克隆)完整的 CVE List V5 仓库。请注意,此仓库大小有数GB,因此下载可能需要一些时间。例如:```bash
sploitscan -local
███████╗██████╗ ██╗ ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗ ██╗
██╔════╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗ ██║
███████╗██████╔╝██║ ██║ ██║██║ ██║ ███████╗██║ ███████║██╔██╗ ██║
╚════██║██╔═══╝ ██║ ██║ ██║██║ ██║ ╚════██║██║ ██╔══██║██║╚██╗██║
███████║██║ ███████╗╚██████╔╝██║ ██║ ███████║╚██████╗██║ ██║██║ ╚████║
╚══════╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝
v0.14.0 / Alexander Hagenah / @xaitax / [email protected]
📥 Cloning CVE List V5 into 'C:\Users\ah/.sploitscan\cvelistV5'.
⚠️ Warning: The repository is several GB in size and the download may take a while.
🔄 Progress: 100.00% - 940.62 MiB | 4.97 MiB/s
✅ CVE List V5 cloned successfully.
通过关键词(例如"Apple")在本地数据库、CISA 和 Nuclei 模板中搜索 CVE。
[!TIP] 这可以或多或少替代 searchsploit,因为 ExploitDB 已经不再定期更新。```bash sploitscan -k "Outlook Express"