Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17038 results
CVE-2025-55182 preview

CVE-2025-55182

GitHubmayca369/cve-2025-55182

Demonstrates CVE-2025-55182 RCE exploit in React Server Functions to highlight insecure prototype references in Next.js, with educational simulation…

vulnerability-analysisexploitationweb-application-exploitation+3
2 days ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubrenzi25031469/cve-2026-19478

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

web-vulnerability-scannersvulnerability-analysisweb-application-exploitation+4
2 days ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

payload-generationvulnerability-analysisexploitation+4
2 days ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker
vulnerability-scannersids-ips-evasionweb-application-exploitation+6
332 days ago
Kittysploit-framework preview

Kittysploit-framework

GitHubsia-iotechnology/kittysploit-framework

Python Exploitation Framework, V8 Engine Debugger, Proxy interceptor, marketplace, post-exploitation, backdoor generator,....

osintpenetration-testing-frameworksreconnaissance+8
5932 days ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

vulnerability-scannersids-ips-evasionweb-application-exploitation+3
3.2k2 days ago
CVE-2026-56848 preview

CVE-2026-56848

GitHubopen-flaw/cve-2026-56848

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

vulnerability-analysisdynamic-code-analysisexploitation+2
2 days ago
PwnzzAI preview

PwnzzAI

GitHubowasp/pwnzzai
vulnerability-analysisweb-securityctf+6
632 days ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

privilege-escalationreconnaissancepassword-attacks+9
2 days ago
caddy preview

caddy

GitHubcaddyserver/caddy

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

general-purpose-utilitiesencryption-decryption-toolsweb-security
74.8k2 days ago
SafeLine preview

SafeLine

GitHubchaitin/safeline

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

vulnerability-scannersdynamic-code-analysisids-ips-evasion+8
22.3k2 days ago
CVE-2026-19598-PoC preview

CVE-2026-19598-PoC

GitHubdeadexpl0it/cve-2026-19598-poc

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

privilege-escalationvulnerability-analysisexploitation+3
2 days ago
vuls preview

vuls

GitHubfuture-architect/vuls

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

vulnerability-scannerscontainer-securityvulnerability-analysis+5
12.2k2 days ago
miasma preview

miasma

GitHubaustin-weeks/miasma

Trap AI web scrapers in an endless poison pit.

osintinformation-gatheringweb-security+3
1.2k2 days ago
CVE-2026-64849 preview

CVE-2026-64849

GitHubbiutrap/cve-2026-64849

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

vulnerability-analysisexploitationweb-application-exploitation+4
2 days ago
CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization preview

CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization

GitHubcypherhippie/cve-2026-34486---unauthenticated-rce-via-java-deserialization

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

payload-generationvulnerability-analysisexploitation+2
2 days ago
CVE-2026-41940-Exploit-PoC preview

CVE-2026-41940-Exploit-PoC

GitHubdefacto-ridgepole254/cve-2026-41940-exploit-poc

Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.

vulnerability-analysisexploitationweb-application-exploitation+3
12 days ago
burner-net preview

burner-net

GitHubkrixx1337/burner-net

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

defensive-toolsencryption-decryption-toolsids-ips-evasion+7
292 days ago
Previous1…678…947Next