本项目是一个以“实战为导向”的 XSS 漏洞练习靶场,覆盖反射型、存储型、DOM 型、SVG、CSP、框架注入、协议绕过等多种场景。页面样式统一,逻辑清晰,适合系统化学习与教学演示
☆42Mar 6, 2026Updated 6 months ago
Alternatives and similar repositories for XSS-Sec
Users that are interested in XSS-Sec are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆19Jun 16, 2026Updated 3 months ago
- 多维度,UI/UX友好的Burp suite越权漏洞检测插件☆41Jul 26, 2026Updated last month
- BpArsenal, a Burp Suite plugin that can quickly convert http requests into command-line tool execution, launch third-party tools and open…☆22Oct 31, 2025Updated 10 months ago
- MatouWebshell 是一款基于 Vue 3 和 Python 开发的开源 Webshell 管理与利用平台。支持高度自定义的流量伪装、内网穿透及内存马注入等功能。项目具有极高的扩展性,非常欢迎安全研究人员基于此开源架构进行二次开发(如自定义修改 Payload、新增…☆22Apr 10, 2026Updated 5 months ago
- hessian反序列化利用工具☆41Apr 11, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- xia_Yue 插件修改版,瞎越修改版,修复中文重放乱码,添加请求行越权测试,一键导出越权url,允许重复url测试等功能☆78Jan 5, 2026Updated 8 months ago
- 鉴穹日志安全分析系统☆18Sep 7, 2025Updated last year
- Remote Code Execution EJS Web Applications using express-fileupload☆12Aug 17, 2021Updated 5 years ago
- 基于 Chrome Manifest V3 的渗透测试辅助插件,用于快速发现页面输入点、评估 CSP 风险、嗅探潜在敏感资产、识别常见前端框架指纹,并内置常用编码转换工具,帮助进行合法合规的渗透测试与安全检查☆74Mar 2, 2026Updated 6 months ago
- This repository is designed to automate the detection and cleanup of in-memory web shells using MCP in combination with the memory-shell-…☆27Jan 14, 2026Updated 8 months ago
- ☆34Aug 28, 2023Updated 3 years ago
- 一个基于 FastAPI + React 的企业级资产管理和关系图谱可视化平台 专为渗透测试团队、安全研究人员和红队打造☆21Jan 30, 2026Updated 7 months ago
- LogTrawl 是一个基于 Wails v2 框架开发的现代化桌面日志分析工具,提供强大的日志查看、搜索、过滤和分析功能。☆87Oct 8, 2025Updated 11 months ago
- pocframe是一个基于python3的开源批量POC检测框架,默认使用协程异步请求,支持多线程并发,支持多种指定目标方式,可用于批量POC检测,也可根据需要扩展功能。☆13Mar 20, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 异常流量检测工具 🚀☆19Nov 21, 2025Updated 9 months ago
- 基于alpine+php7.3的一个RCE命令执行靶场,包含基础命令、shell 特性、常见姿势、常见waf绕过☆64Jul 8, 2026Updated 2 months ago
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,138Updated this week
- 【Hello-CTF labs】一个ssrf的综合靶场,包含RCE,SQL注入,Tomcat,Redis,MySQL提权等ssrf攻击场景☆88Mar 18, 2025Updated last year
- Burpsuite验证码DOS攻击插件。☆21Oct 24, 2024Updated last year
- 一个应急响应的工具,自带规则,可以分析启动项、网络之类的东西☆78Jul 23, 2025Updated last year
- [VscanPlus内外网漏洞扫描工具]已更新HW热门漏洞检测POC。基于veo师傅的漏扫工具vscan二次开发的版本,端口扫描、指纹检测、目录fuzz、漏洞扫描功能工具,批量快速检测网站安全隐患。An open-source, cross-platform websit…☆351Mar 10, 2026Updated 6 months ago
- WriteUp For BUUCTF-Pwn☆12Dec 5, 2022Updated 3 years ago
- Enhanced Repeater Manager - Burp Suite 增强重放插件☆18Aug 13, 2026Updated last month
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- 微信公众号安全漏洞文章链接聚合☆40Updated this week
- Shiro反序列化漏洞一站式综合利用工具☆172Jan 22, 2026Updated 7 months ago
- 渗透测试快速启动工具☆17Oct 21, 2025Updated 10 months ago
- 面向全平台愿景的原生 AI 桌面助手,支持 Live2D 角色交互与 OpenAI 兼容对话/TTS API。 | A cross-platform and native vision AI desktop assistant with Live2D character i…☆23Apr 16, 2026Updated 5 months ago
- RVScan 是一个功能强大的 Burp Suite 扩展插件,专为自动化Web应用程序安全测试和漏洞扫描而设计。它提供全面的路径发现、绕过技术、EHole指纹识别和可定制的扫描规则。☆203May 6, 2026Updated 4 months ago
- 基于mitmproxy的安全工具,支持请求自动加解密、webpack优化、流量关键字查询。☆89Jan 5, 2026Updated 8 months ago
- Automation tool designed to simplify the analysis of PCAP (Packet Capture) files☆20Mar 31, 2026Updated 5 months ago
- ☆35Sep 21, 2025Updated 11 months ago
- burp越权测试插件☆20Sep 3, 2026Updated 2 weeks ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- 详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件☆17Jun 30, 2025Updated last year
- xxl_job_executor_默认Access_Token_不出网综合利用☆43Oct 20, 2025Updated 11 months ago
- S-XIASQL 是一款专业的 Burp Suite SQL注入检测插件,能够自动化检测Web应用中的SQL注入漏洞。通过智能分析HTTP请求响应,快速识别潜在的SQL注入点,大幅提升渗透测试效率。☆101Mar 16, 2026Updated 6 months ago
- 网站渗透测试 Skill — 目标识别、CDN/WAF检测、指纹架构、API发现、端口扫描、未授权与漏洞验证☆30Jun 8, 2026Updated 3 months ago
- ByPassTamperPlus / SQLMap加强绕WAF / Code By:Tas9er☆121Feb 12, 2026Updated 7 months ago
- This vulnerability could allow an attacker to take complete control of a vulnerable Confluence server. This could allow the attacker to s…☆11May 24, 2024Updated 2 years ago
- 一个记录本机IP的小程序☆35Jan 8, 2025Updated last year