Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Web Security | Kitploit
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17039 results
CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass preview
Archived

CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass

GitHubdevdungeon/cve-2019-6340-drupal-8.6.9-rest-auth-bypass

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

payload-generationvulnerability-analysisexploitation+3
2
7 years ago
CVE-2020-36109-POC preview
Archived

CVE-2020-36109-POC

GitHubtin-z/cve-2020-36109-poc

PoC DoS CVE-2020-36109

vulnerability-analysisexploitationweb-security+1
23 years ago
pyshellshock preview
Archived

pyshellshock

GitHubramnes/pyshellshock

😱 Python library and utility for CVE-2014-6271 (aka. "shellshock")

vulnerability-analysiscode-analysisexploitation+2
29 years ago
nodejs-http-transfer-encoding-smuggling-poc preview
Archived

nodejs-http-transfer-encoding-smuggling-poc

GitHubprogfay/nodejs-http-transfer-encoding-smuggling-poc

PoC of HTTP Request Smuggling in nodejs (CVE-2020-8287)

vulnerability-analysisexploitationweb-application-exploitation+2
25 years ago
react2shell preview
Archived

react2shell

GitHubmantvmass/react2shell

A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code…

vulnerability-scannersexploitationweb-application-exploitation+3
28 months ago
CVE-2021-41773_Honeypot preview
Archived

CVE-2021-41773_Honeypot

GitHublopqto/cve-2021-41773_honeypot

Simple honeypot for CVE-2021-41773 vulnerability

defensive-toolsvulnerability-analysisweb-security+2
24 years ago
CVE-2023-20860 preview
Archived

CVE-2023-20860

GitHublimo520/cve-2023-20860
vulnerability-analysisexploitationweb-application-exploitation+2
23 years ago
ApacheRCEEssay preview
Archived

ApacheRCEEssay

GitHubiosifache/apacherceessay

Essay (and PoCs) about CVE-2021-41773, a remote code execution vulnerability in Apache 2.4.49 🕸️

vulnerability-analysisexploitationweb-security+3
24 years ago
heartthreader preview
Archived

heartthreader

GitHubcyphar/heartthreader

Mass, multithreaded testing for servers against Heartbleed (CVE-2014-0160).

vulnerability-scannersexploitationweb-security+2
212 years ago
CVE-2025-8730 preview
Archived

CVE-2025-8730

GitHubbytereaper77/cve-2025-8730

Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.

vulnerability-analysisexploitationweb-application-exploitation+3
21 year ago
CVE-2025-8471 preview
Archived

CVE-2025-8471

GitHubbytereaper77/cve-2025-8471

Exploit SQL injection in projectworlds Online Admissions System v1.0

vulnerability-analysisexploitationweb-application-exploitation+1
21 year ago
CVE-2025-8191 preview
Archived

CVE-2025-8191

GitHubbytereaper77/cve-2025-8191

A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.

vulnerability-analysisexploitationweb-application-exploitation+3
21 year ago
CVE-2025-7840 preview
Archived

CVE-2025-7840

GitHubbytereaper77/cve-2025-7840

Proof‑of‑concept exploit for CVE‑2025‑7840 that injects malicious payloads into the Firstname parameter of a reservation form to trigger XSS

payload-generationvulnerability-analysisexploitation+3
21 year ago
CVE-2025-7795 preview
Archived

CVE-2025-7795

GitHubbytereaper77/cve-2025-7795

Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests…

embedded-systems-securityiot-securityvulnerability-analysis+3
21 year ago
CVE-2025-7753 preview
Archived

CVE-2025-7753

GitHubbytereaper77/cve-2025-7753

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

vulnerability-analysisexploitationweb-application-exploitation+1
21 year ago
CVE-2025-6860 preview
Archived

CVE-2025-6860

GitHubbytereaper77/cve-2025-6860

A proof‑of‑concept command‑line tool in C for detecting the SQL injection vulnerability .

vulnerability-scannerspayload-generationexploitation+2
21 year ago
CVE-2025-5964- preview
Archived

CVE-2025-5964-

GitHubbytereaper77/cve-2025-5964-

C PoC language for emulating path traversal vulnerability (CVE-2025-5964) in M-Files25.6.14925.0

vulnerability-analysisexploitationweb-application-exploitation+3
21 year ago
CVE-2025-54769 preview
Archived

CVE-2025-54769

GitHubbytereaper77/cve-2025-54769

A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade…

payload-generationvulnerability-analysisexploitation+3
21 year ago
Previous1…941942943…947Next