Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Web Security | Kitploit
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17039 results
Black-Tool preview

Black-Tool

GitHubmrprogrammer2938/black-tool

Install the tools and start Attacking , black-tool v5.5.5 ! ⬛

penetration-testing-frameworksphishing-toolspassword-attacks+4
641
2 years ago
crackerjack preview

crackerjack

GitHubctxis/crackerjack

CrackerJack / Hashcat Web Interface / Context Information Security

password-crackingweb-application-exploitationpenetration-testing+1
3782 years ago
extended-xss-search preview

extended-xss-search

GitHubdamian89/extended-xss-search

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

vulnerability-scannersweb-vulnerability-scannersinformation-gathering+2
1897 years ago
Crawlector preview

Crawlector

GitHubmfmokbel/crawlector

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

osintvulnerability-scannersthreat-feeds-aggregators+5
1238 months ago
mzap preview

mzap

GitHubhahwul/mzap

⚡️ Multiple target ZAP Scanning

vulnerability-scannersdynamic-analysis-sandboxingapi-security-testing+3
11228 days ago
Pegasus---Forbidden-Buster preview

Pegasus---Forbidden-Buster

GitHubsobri3195/pegasus---forbidden-buster

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

vulnerability-scannersids-ips-evasioninformation-gathering+3
31 year ago
CVE-2023-26692 preview

CVE-2023-26692

GitHubbigzooooz/cve-2023-26692

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

vulnerability-analysisexploitationweb-application-exploitation+2
13 years ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

privilege-escalationreconnaissancepassword-attacks+9
3 days ago
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationweb-application-exploitationweb-security+3
11 day ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

payload-generationvulnerability-analysisexploitation+4
1 day ago
CVE-2026-19598-PoC preview

CVE-2026-19598-PoC

GitHubdeadexpl0it/cve-2026-19598-poc

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

privilege-escalationvulnerability-analysisexploitation+3
2 days ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

vulnerability-scannersexploitationweb-application-exploitation+3
12 years ago
CVE-2026-6837-zyxel-export-cgi-command-injection preview

CVE-2026-6837-zyxel-export-cgi-command-injection

GitHubminanagehsalalma/cve-2026-6837-zyxel-export-cgi-command-injection

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

embedded-systems-securityvulnerability-analysisexploitation+3
4 days ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationosintpenetration-testing-frameworks+8
734 days ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

privilege-escalationpayload-generationvulnerability-analysis+7
79.9k11 days ago
caddy preview

caddy

GitHubcaddyserver/caddy

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

general-purpose-utilitiesencryption-decryption-toolsweb-security
74.8k2 days ago
Scrapling preview

Scrapling

GitHubd4vinci/scrapling

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

dynamic-analysis-sandboxingweb-securitycrawler+2
73.4k1 day ago
SecLists preview

SecLists

GitHubdanielmiessler/seclists

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

password-crackingreconnaissanceweb-security+3
72.8k18h 36m ago
Previous1234…947Next