Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Web Application Exploitation

Tools specifically designed to exploit common web application vulnerabilities (e.g., SQL injection, XSS).

NewestRelevanceMost popularRecently updated
13161 results
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationweb-application-exploitationweb-security+3
1
21h 40m ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHublanicer/cve-2026-41940-poc

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

authentication-authorizationprivilege-escalationvulnerability-scanners+5
291 day ago
CVE-2021-42013_821311 preview

CVE-2021-42013_821311

GitHubandreamammano89-maker/cve-2021-42013_821311

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

vulnerability-analysisexploitationweb-application-exploitation+1
1 day ago
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

vulnerability-analysisexploitationweb-application-exploitation+3
22h 58m ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

vulnerability-scannersexploitationweb-application-exploitation+3
0 days ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

vulnerability-scannersexploitationweb-application-exploitation+3
12 years ago
CVE-2026-64849 preview

CVE-2026-64849

GitHubbiutrap/cve-2026-64849

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

vulnerability-analysisexploitationweb-application-exploitation+4
1 day ago
CVE-2026-19598-PoC preview

CVE-2026-19598-PoC

GitHubdeadexpl0it/cve-2026-19598-poc

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

privilege-escalationvulnerability-analysisexploitation+3
1 day ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

payload-generationvulnerability-analysisexploitation+4
1 day ago
POC-CVE-2026-63030-CVE-2026-60137- preview

POC-CVE-2026-63030-CVE-2026-60137-

GitHubtrandonga3/poc-cve-2026-63030-cve-2026-60137-

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

privilege-escalationvulnerability-analysisexploitation+6
1 day ago
CVE-2025-24893_Analysis preview

CVE-2025-24893_Analysis

GitHubmattiacervelli/cve-2025-24893_analysis

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

payload-generationvulnerability-analysisexploitation+5
1 day ago
CVE-2026-53959 preview

CVE-2026-53959

GitHubanirbala98/cve-2026-53959

4gaBoards < 3.3.9 - User Information Disclosure

vulnerability-analysisexploitationweb-application-exploitation+5
11 day ago
CVE-2025-24799 preview

CVE-2025-24799

GitHubrosemary1337/cve-2025-24799

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

vulnerability-analysisexploitationweb-application-exploitation+2
11 months ago
grav-cve-2024-28116 preview

grav-cve-2024-28116

GitHubbebarossi/grav-cve-2024-28116

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

vulnerability-analysisexploitationweb-application-exploitation+3
1 day ago
CVE-2025-6934 preview

CVE-2025-6934

GitHubrosemary1337/cve-2025-6934

Automated PoC exploit for WordPress Opal Estate Pro that detects vulnerable versions, retrieves nonce, and creates unauthorized administrator…

vulnerability-analysisexploitationweb-application-exploitation+3
11 months ago
CVE-2026-40179-PoC preview

CVE-2026-40179-PoC

GitHubbsdrip/cve-2026-40179-poc

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

vulnerability-analysisexploitationweb-application-exploitation+1
1 day ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubrenzi25031469/cve-2026-19478

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

web-vulnerability-scannersvulnerability-analysisweb-application-exploitation+4
1 day ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubkaleth4/cve-2026-64638

Technical analysis and defensive mitigation for a WordPress Core pre-auth XSS-to-RCE chain, including sanitizer bypass, DOM clobbering, JSONP abuse,…

vulnerability-analysisexploitationweb-application-exploitation+3
1 day ago
Previous12…732Next