Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories

工具

全部Android安全身份验证与授权云基础设施安全防御工具磁盘取证嵌入式系统安全通用工具危害指标 (IOC) 管理OSINT (开源情报)数据包嗅探与分析密码破解渗透测试框架钓鱼工具权限提升侦察静态分析漏洞扫描器Web漏洞扫描器Wi-Fi审计蓝牙安全容器安全动态分析 (沙盒)加密/解密工具漏洞利用框架身份管理iOS安全物联网安全内存取证网络映射社会工程学OSINT密码攻击Payload生成持久化机制端口扫描静态代码分析 (SAST)威胁源与聚合器漏洞分析Web代理与拦截代码分析DNS和子域名枚举动态代码分析 (DAST)漏洞利用哈希分析IDS/IPS规避冒充工具横向移动移动应用渗透测试网络取证逆向工程RFID/NFC工具SCADA/ICS安全脚本与自动化无服务器安全ShellcodeWeb应用程序漏洞利用API安全测试配置审计数据泄露调试器取证分析信息收集移动取证网络访问控制后渗透利用安全虚拟化钓鱼攻击WAF绕过Web安全模糊测试网络安全隐写术无线安全数据恢复恶意软件分析数字取证硬件黑客密码学CTF渗透测试云安全DevSecOps移动安全隐私保护命令与控制社会工程学硬件安全实用工具与框架硬件与物联网安全秘密检测二进制分析威胁情报身份与访问管理 (IAM)供应链安全身份验证机器学习入侵检测论文与研究错误配置子域名枚举电子邮件收集学习与教育AI 辅助逆向DNS 模糊测试红队事件响应网络爬虫精选资源远程访问工具Shellcode 生成Payload 开发远程访问木马API 安全反机器人指纹欺骗CAPTCHA 绕过电子邮件安全DNS 分析混沌工程学习路径与课程容器逃逸AI 安全数据库安全固件分析异常检测日志分析对抗性攻击二进制利用实验室与实践
最新相关性最受欢迎最近更新
3294 结果
内容在请求的语言中不可用。显示英文版本。
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms 插件单请求 RCE(通过 URL),PoC + 漏洞利用链

exploitationweb-application-exploitationweb-security+3
1
11小时26分前
CVE-2026-43499_HW-CLT-AL01 preview

CVE-2026-43499_HW-CLT-AL01

GitHubzychen027/cve-2026-43499_hw-clt-al01

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

android-securityprivilege-escalationexploitation+4
0天前
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2启动套件,通过NVRAM启动选项安装预启动网络植入物,链式加载UKI,执行dracut载荷,并通过kexec加载原厂内核。

persistence-mechanismsdata-exfiltrationpost-exploitation+5
1天前
dyen preview

dyen

GitHubcenobyte-vincit/dyen

适用于原版 macOS Python 的内存中 Mach-O dylib 加载器;无需 dlopen 或写入磁盘即可解密、映射并运行载荷,支持可选的加密掩护文件嵌入。

payload-generationids-ips-evasionpost-exploitation+4
1天前
CVE-2020-14882-WebLogic-Analysis preview

CVE-2020-14882-WebLogic-Analysis

GitHubvelessecurity/cve-2020-14882-weblogic-analysis

技术分析与干净的 Java Thread Echo PoC,针对 Oracle WebLogic Server 漏洞链。

vulnerability-analysisexploitationweb-application-exploitation+1
1天前
CVE-2026-14669 preview

CVE-2026-14669

GitHubhackspeak/cve-2026-14669

针对 CVE-2026-14669 的概念验证漏洞利用程序,该漏洞为 PostgreSQL to_char() 时区缩写中的堆缓冲区溢出,可通过信息泄露和 ROP 链实现 RCE(远程代码执行);包含 Docker 实验环境与自动化 PoC。

vulnerability-analysisexploitationpenetration-testing+4
11天前
ghostlock-cve-2026-43499 preview

ghostlock-cve-2026-43499

GitHubgitchw/ghostlock-cve-2026-43499

CVE-2026-43499 (GhostLock) — Linux 内核 futex PI rt_mutex UAF ARM32 权限提升研究,针对华为 Watch 4 Pro(内核 5.4.210)

embedded-systems-securityprivilege-escalationiot-security+5
1天前
hp-slate7-root-kit preview

hp-slate7-root-kit

GitHubvalentineus/hp-slate7-root-kit

HP Slate 7 2800 Android 4.1.1 的 Root 工具包,利用 CVE-2015-1805 漏洞。

android-securityprivilege-escalationpersistence-mechanisms+6
11天前
CVE-2026-33017-FireFlow preview

CVE-2026-33017-FireFlow

GitHubl4st98/cve-2026-33017-fireflow

针对 Langflow CVE-2026-33017 的概念验证 RCE,利用恶意自定义组件通过 build_public_tmp 执行操作系统命令,并从作业事件中获取输出。

exploitationweb-application-exploitationctf+4
2天前
cve-2026-41042 preview

cve-2026-41042

GitHublulztigre/cve-2026-41042

通过 H2 JDBC INIT 利用 Apache Gravitino < 1.2.1 中的未认证 RCE;托管 SQL/Java 载荷、执行命令,并通过 HTTP beacon 回传输出。

vulnerability-analysisexploitationweb-application-exploitation+2
2天前
CVE-2026-20079 preview

CVE-2026-20079

GitHubcyberauth/cve-2026-20079

针对 Cisco Secure FMC 实现 CVE-2026-20079 认证绕过至 root RCE 的利用链,支持指纹识别、检测、验证和交互式利用模式。

vulnerability-analysisexploitationweb-application-exploitation+3
2天前
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154 · CometChat JS SDK 中的存储型 XSS

vulnerability-analysisexploitationweb-application-exploitation+4
2天前
CVE-2026-13714 preview

CVE-2026-13714

GitHubkatransefa/cve-2026-13714

针对 Realtyna WPL < 5.3.0 的未认证 RCE 漏洞利用,可通过硬编码的 API 密钥上传 PHP WebShell 并执行任意系统命令。

exploitationweb-application-exploitationpost-exploitation+2
2天前
CVE-2026-17544 preview

CVE-2026-17544

GitHubr2qa/cve-2026-17544

CVE-2026-17544 漏洞利用程序:将 PHP bcmath 越界写入(OOB write)转化为纯内存 RCE,借助运行时无偏移解析器绕过 disable_functions 和 open_basedir。

vulnerability-analysisexploitationweb-application-exploitation+4
4天前
POC-GeoLeak-CVE-2026-52715 preview

POC-GeoLeak-CVE-2026-52715

GitHub686f6c61/poc-geoleak-cve-2026-52715

CVE-2026-52715(GeoLeak)的功能性PoC:GEO my WordPress <= 4.5.5 中通过 swlatlng/nelatlng 实现的未认证 SQLi。Docker 实验室 + 基于时间/基于布尔的漏洞利用 + 载荷中无逗号的渗出。

vulnerability-analysisexploitationweb-application-exploitation+4
5天前
MouseServer-1.7.8.5-RCE preview

MouseServer-1.7.8.5-RCE

GitHubmermehr/mouseserver-1.7.8.5-rce

针对 WiFi Mouse Server 1.7.8.5 的 CVE-2022-3218 PoC 漏洞利用,通过按键注入和内存 PowerShell 载荷投递实现 RCE,适用于加固的实验室环境。

vulnerability-analysisexploitationpenetration-testing+2
4天前
CVE-2025-64512-pdfminer-PoC preview

CVE-2025-64512-pdfminer-PoC

GitHuboguzylmzx/cve-2025-64512-pdfminer-poc

针对 CVE-2025-64512 的 PoC:pdfminer.six CMapDB pickle 反序列化 RCE(通过特制 PDF 触发)

payload-generationvulnerability-analysisexploitation+3
4天前
CVE-2024-56426 preview

CVE-2024-56426

GitHubxcracker000/cve-2024-56426

适用于 Exynos 9830 bootROM 的漏洞利用工具包,可为三星 SM-G985F 设备提供签名启动绕过、自定义密钥注入和内存转储载荷。

android-securityembedded-systems-securityexploitation+7
14天前
上一页12…183下一页