Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17039 results
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

web-vulnerability-scannersexploitationweb-application-exploitation+4
2
2 days ago
CVE-2026-19650-CVE-2026-19478 preview

CVE-2026-19650-CVE-2026-19478

GitHubhorkimhab/cve-2026-19650-cve-2026-19478

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

vulnerability-analysisexploitationweb-application-exploitation+4
3 days ago
impersonate-proxy preview

impersonate-proxy

GitHubytkoka/impersonate-proxy

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

web-proxies-interceptionimpersonation-toolswaf-bypass+3
72 days ago
AI-Vulnerability-Remediation-Study preview

AI-Vulnerability-Remediation-Study

GitHubnitindevelopermca/ai-vulnerability-remediation-study

Study of CVE-2018-6341 in React, demonstrating AI-assisted vulnerability detection, root-cause analysis, and remediation guidance for JavaScript…

vulnerability-analysiscode-analysisweb-security+2
14 days ago
masq preview

masq

GitLabwattocyber/masq

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

reconnaissancestatic-analysisvulnerability-analysis+6
3 days ago
CVE-2026-33017-FireFlow preview

CVE-2026-33017-FireFlow

GitHubl4st98/cve-2026-33017-fireflow

Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

exploitationweb-application-exploitationctf+4
3 days ago
CVE-2026-74251 preview

CVE-2026-74251

GitHubtoanln-cov/cve-2026-74251

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

vulnerability-analysisexploitationweb-application-exploitation+3
3 days ago
CVE-2026-40345 preview

CVE-2026-40345

GitHubjvr2022/cve-2026-40345

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

vulnerability-scannersvulnerability-analysisexploitation+3
13 days ago
cve-2026-41042 preview

cve-2026-41042

GitHublulztigre/cve-2026-41042

Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…

vulnerability-analysisexploitationweb-application-exploitation+2
3 days ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

vulnerability-scannerspayload-generationport-scanning+6
14 days ago
EITS-Portal-Exploit-CVE-2026-31367-PoC preview

EITS-Portal-Exploit-CVE-2026-31367-PoC

GitHubhereticl1nk/eits-portal-exploit-cve-2026-31367-poc

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

vulnerability-analysisexploitationweb-application-exploitation+2
4 days ago
CVE-2026-26980 preview

CVE-2026-26980

GitHubvognik/cve-2026-26980

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

vulnerability-analysisexploitationweb-application-exploitation+4
104 days ago
CVE-2026-20079 preview

CVE-2026-20079

GitHubcyberauth/cve-2026-20079

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

vulnerability-analysisexploitationweb-application-exploitation+3
3 days ago
CVE-2026-59310 preview

CVE-2026-59310

GitHubbiutrap/cve-2026-59310

Proof-of-concept exploit for CVE-2026-59310, demonstrating remote path traversal via crafted syslog messages to write arbitrary log files on VMware…

vulnerability-analysisexploitationweb-application-exploitation+2
3 days ago
CVE-2026-71203-PoC preview

CVE-2026-71203-PoC

GitHubnel-droid/cve-2026-71203-poc

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

vulnerability-analysisexploitationapi-security-testing+4
4 days ago
CVE-2026-71204-PoC preview

CVE-2026-71204-PoC

GitHubnel-droid/cve-2026-71204-poc

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

authentication-authorizationvulnerability-analysisexploitation+2
4 days ago
CVE-2026-71205-PoC preview

CVE-2026-71205-PoC

GitHubnel-droid/cve-2026-71205-poc

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

password-attacksvulnerability-analysisexploitation+4
4 days ago
CVE-2026-71206-PoC preview

CVE-2026-71206-PoC

GitHubnel-droid/cve-2026-71206-poc

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

authentication-authorizationvulnerability-analysisexploitation+3
4 days ago
Previous1…345…947Next