Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17039 results
PoC-in-GitHub preview

PoC-in-GitHub

GitHubnomi-sec/poc-in-github

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

exploit-frameworksvulnerability-analysisexploitation+5
8.0k1 day ago
patchright preview

patchright

GitHubkaliiiiiiiiii-vinyzu/patchright

Undetected version of the Playwright testing and automation library.

ids-ips-evasionwaf-bypasscrawler+2
4.1k1 day ago
BrowserBox preview

BrowserBox

GitHubbrowserbox/browserbox

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

defensive-toolsweb-securitynetwork-security+3
3.9k1 day ago
VulnReach preview

VulnReach

GitHubowasp/vulnreach

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+5
81 day ago
Scrapling preview

Scrapling

GitHubd4vinci/scrapling

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

dynamic-analysis-sandboxingweb-securitycrawler+2
73.4k1 day ago
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationweb-application-exploitationweb-security+3
11 day ago
vigolium preview

vigolium

GitHubvigolium/vigolium

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

vulnerability-scannersweb-vulnerability-scannersdynamic-analysis-sandboxing+9
9711 day ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

defensive-toolsvulnerability-analysisweb-security+5
1.6k1 day ago
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

vulnerability-analysisexploitationweb-application-exploitation+3
1 day ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

vulnerability-scannersexploitationweb-application-exploitation+3
1 day ago
noir preview

noir

GitHubowasp-noir/noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

static-analysisvulnerability-analysisweb-security+3
1.4k1 day ago
CVE-2021-42013_821311 preview

CVE-2021-42013_821311

GitHubandreamammano89-maker/cve-2021-42013_821311

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

vulnerability-analysisexploitationweb-application-exploitation+1
1 day ago
spider preview

spider

GitHubspider-rs/spider

Get web data for AI agents and LLMs

information-gatheringweb-securitycrawler+2
2.6k1 day ago
EasySpider preview

EasySpider

GitHubnaibowang/easyspider

A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别名:ServiceWrapper面向Web应用的智能化服务封装系统。

scripting-automationweb-securityeducation+1
44.4k1 day ago
DVWA preview

DVWA

GitHubdigininja/dvwa

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

vulnerability-analysisweb-securitypenetration-testing+2
13.5k1 day ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHublanicer/cve-2026-41940-poc

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

authentication-authorizationprivilege-escalationvulnerability-scanners+5
291 day ago
wstg preview

wstg

GitHubowasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

vulnerability-analysisweb-securitypenetration-testing+1
9.7k2 days ago
CVE-2025-24893_Analysis preview

CVE-2025-24893_Analysis

GitHubmattiacervelli/cve-2025-24893_analysis

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

payload-generationvulnerability-analysisexploitation+5
2 days ago
Previous1…456…947Next