Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Web Security | Kitploit
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17039 results
CVE-2026-71205-PoC preview

CVE-2026-71205-PoC

GitHubnel-droid/cve-2026-71205-poc

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

password-attacksvulnerability-analysisexploitation+4
4 days ago
CVE-2026-71206-PoC preview

CVE-2026-71206-PoC

GitHubnel-droid/cve-2026-71206-poc

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

authentication-authorizationvulnerability-analysisexploitation+3
4 days ago
CVE-2026-72585-PoC preview

CVE-2026-72585-PoC

GitHubnel-droid/cve-2026-72585-poc

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

authentication-authorizationvulnerability-analysisexploitation+2
4 days ago
React2Shell preview

React2Shell

GitHubphanhoangkhang/react2shell

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+6
4 days ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubaleewyy/cve-2025-49132

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

vulnerability-analysisexploitationweb-application-exploitation+3
2 months ago
Palimpsest preview

Palimpsest

GitHubdefineid/palimpsest

CVE-2026-74945 · Uninitialized heap disclosure via a crafted web font (sec-high)

payload-generationvulnerability-analysisexploitation+1
3 days ago
Revenant preview

Revenant

GitHubdefineid/revenant

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

vulnerability-analysiscode-analysisexploitation+3
3 days ago
SkeletonKey preview

SkeletonKey

GitHubdefineid/skeletonkey

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox

vulnerability-analysisexploitationdata-exfiltration+3
3 days ago
Trespasser preview

Trespasser

GitHubdefineid/trespasser

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

vulnerability-analysisexploitationweb-application-exploitation+1
3 days ago
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154 · Stored XSS in CometChat JS SDK

vulnerability-analysisexploitationweb-application-exploitation+4
3 days ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubkatransefa/cve-2026-13714

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

exploitationweb-application-exploitationpost-exploitation+2
3 days ago
CVE-2023-22515 preview

CVE-2023-22515

GitHubs1incere/cve-2023-22515

Confluence Unauthorized Administrator User Addition Exploitation Script

authentication-authorizationvulnerability-analysisexploitation+3
254 months ago
security-research preview

security-research

GitHubpig-tail/security-research

PoCs & write-ups for CVEs I reported (coordinated disclosure; published + patched only)

vulnerability-analysisexploitationweb-application-exploitation+1
111 days ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubnxploited/cve-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

privilege-escalationweb-vulnerability-scannersexploitation+3
4 days ago
Security_incident_report preview

Security_incident_report

GitHubkevin9480/security_incident_report

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트

vulnerability-analysisweb-securitynetwork-security+5
4 days ago
CVE-2026-20896-Gitea-Authentication-Bypass preview

CVE-2026-20896-Gitea-Authentication-Bypass

GitHubjudgedbykira/cve-2026-20896-gitea-authentication-bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

vulnerability-analysisexploitationweb-application-exploitation+5
5 days ago
nullorigin preview

nullorigin

GitHubrakib-nyc/nullorigin

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

static-code-analysisweb-proxies-interceptionsteganography+4
44 days ago
CVE-2026-73519-WolfStack-PoC preview

CVE-2026-73519-WolfStack-PoC

GitHubsqueeze440/cve-2026-73519-wolfstack-poc

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

container-securityvulnerability-analysisexploitation+3
5 days ago
Previous1…456…947Next