本项目是一个以“实战为导向”的 XSS 漏洞练习靶场,覆盖反射型、存储型、DOM 型、SVG、CSP、框架注入、协议绕过等多种场景。页面样式统一,逻辑清晰,适合系统化学习与教学演示
☆36Mar 6, 2026Updated 5 months ago
Alternatives and similar repositories for XSS-Sec
Users that are interested in XSS-Sec are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆19Jun 16, 2026Updated 2 months ago
- 多维度,UI/UX友好的Burp suite越权漏洞检测插件☆36Jul 26, 2026Updated last month
- BpArsenal, a Burp Suite plugin that can quickly convert http requests into command-line tool execution, launch third-party tools and open…☆22Oct 31, 2025Updated 10 months ago
- MatouWebshell 是一款基于 Vue 3 和 Python 开发的开源 Webshell 管理与利用平台。支持高度自定义的流量伪装、内网穿透及内存马注入等功能。项目具有极高的扩展性,非常欢迎安全研究人员基于此开源架构进行二次开发(如自定义修改 Payload、新增…☆23Apr 10, 2026Updated 4 months ago
- hessian反序列化利用工具☆42Apr 11, 2026Updated 4 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- xia_Yue 插件修改版,瞎越修改版,修复中文重放乱码,添加请求行越权测试,一键导出越权url,允许重复url测试等功能☆79Jan 5, 2026Updated 7 months ago
- 鉴穹日志安全分析系统☆18Sep 7, 2025Updated 11 months ago
- Remote Code Execution EJS Web Applications using express-fileupload☆12Aug 17, 2021Updated 5 years ago
- 基于 Chrome Manifest V3 的渗透测试辅助插件,用于快速发现页面输入点、评估 CSP 风险、嗅探潜在敏感资产、识别常见前端框架指纹,并内置常用编码转换工具,帮助进行合法合规的渗透测试与安全检查☆75Mar 2, 2026Updated 5 months ago
- This repository is designed to automate the detection and cleanup of in-memory web shells using MCP in combination with the memory-shell-…☆25Jan 14, 2026Updated 7 months ago
- ☆34Aug 28, 2023Updated 3 years ago
- LogTrawl 是一个基于 Wails v2 框架开发的现代化桌面日志分析工具,提供强大的日志查看、搜索、过滤和分析功能。☆86Oct 8, 2025Updated 10 months ago
- pocframe是一个基于python3的开源批量POC检测框架,默认使用协程异步请求,支持多线程并发,支持多种指定目标方式,可用于批量POC检测,也可根据需要扩展功能。☆13Mar 20, 2021Updated 5 years ago
- 一个基于 FastAPI + React 的企业级资产管理和关系图谱可视化平台 专为渗透测试团队、安全研究人员和红队打造☆20Jan 30, 2026Updated 7 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- 异常流量检测工具 🚀☆19Nov 21, 2025Updated 9 months ago
- 基于alpine+php7.3的一个RCE命令执行靶场,包含基础命令、shell 特性、常见姿势、常见waf绕过☆62Jul 8, 2026Updated last month
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞 ,实战导向,助力安全研究与合规检测。☆1,098Updated this week
- 【Hello-CTF labs】一个ssrf的综合靶场,包含RCE,SQL注入,Tomcat,Redis,MySQL提权等ssrf攻击场景☆86Mar 18, 2025Updated last year
- Burpsuite验证码DOS攻击插件。☆21Oct 24, 2024Updated last year
- 一个应急响应的工具,自带规则,可以分析启动项、网络之类的东西☆78Jul 23, 2025Updated last year
- [VscanPlus内外网漏洞扫描工具]已更新HW热门漏洞检测POC。基于veo师傅的漏扫工具vscan二次开发的版本,端口扫描、指纹检测、目录fuzz、漏洞扫描功能工具,批量快速检测网站安全隐患。An open-source, cross-platform websit…☆351Mar 10, 2026Updated 5 months ago
- WriteUp For BUUCTF-Pwn☆12Dec 5, 2022Updated 3 years ago
- Enhanced Repeater Manager - Burp Suite 增强重放插件☆18Aug 13, 2026Updated 2 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- 微信公众号安全漏洞文章链接聚合☆39Updated this week
- Shiro反序列化漏洞一站式综合利用工具☆174Jan 22, 2026Updated 7 months ago
- 渗透测试快速启动工具☆17Oct 21, 2025Updated 10 months ago
- 面向全平台愿景的原生 AI 桌面助手,支持 Live2D 角色交互与 OpenAI 兼容对话/TTS API。 | A cross-platform and native vision AI desktop assistant with Live2D character i…☆22Apr 16, 2026Updated 4 months ago
- RVScan 是一个功能强大的 Burp Suite 扩展插件,专为自动化Web应用程序安全测试和漏洞扫描而设计。它提供全面的路径发现、绕过技术、EHole指纹识别和可定制的扫描规则。☆204May 6, 2026Updated 3 months ago
- 基于mitmproxy的安全工具,支持请求自动加解密、webpack优化、流量关键字查询。☆89Jan 5, 2026Updated 7 months ago
- ☆35Sep 21, 2025Updated 11 months ago
- Automation tool designed to simplify the analysis of PCAP (Packet Capture) files☆19Mar 31, 2026Updated 5 months ago
- burp越权测试插件☆19May 15, 2026Updated 3 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- 详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件☆17Jun 30, 2025Updated last year
- xxl_job_executor_默认Access_Token_不出网综合利用☆42Oct 20, 2025Updated 10 months ago
- 一款集成了Nuclei模板管理、多空间引擎搜索的网络安全工具集。为安全研究人员提供高效的工作体验。☆23Mar 16, 2026Updated 5 months ago
- 网站渗透测试 Skill — 目标识别、CDN/WAF检测、指纹架构、API发现、端口扫描、未授权与漏洞验证☆30Jun 8, 2026Updated 2 months ago
- ByPassTamperPlus / SQLMap加强绕WAF / Code By:Tas9er☆124Feb 12, 2026Updated 6 months ago
- S-XIASQL 是一款专业的 Burp Suite SQL注入检测插件,能够自动化检测Web应用中的SQL注入漏洞。通过智能分析HTTP请求响应,快速识别潜在的SQL注入点,大幅提升渗透测试效率。☆99Mar 16, 2026Updated 5 months ago
- This vulnerability could allow an attacker to take complete control of a vulnerable Confluence server. This could allow the attacker to s…☆11May 24, 2024Updated 2 years ago