Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Exploitation

Tools for weaponizing vulnerabilities to gain unauthorized access to systems or data.

NewestRelevanceMost popularRecently updated
23064 results
CVE-2026-28134 preview

CVE-2026-28134

GitHubrandomrobbiebf/cve-2026-28134

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

vulnerability-analysisexploitationweb-application-exploitation+1
5 months ago
CVE-2025-67923 preview

CVE-2025-67923

GitHubrandomrobbiebf/cve-2025-67923

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

vulnerability-analysisexploitationweb-application-exploitation+2
5 months ago
CVE-2026-2413 preview

CVE-2026-2413

GitHubrandomrobbiebf/cve-2026-2413

Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path

vulnerability-analysisexploitationweb-application-exploitation+1
5 months ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubk3ystr0k3r/cve-2026-39987

Proof-of-concept exploit for Marimo pre-authentication RCE. Uses the unauthenticated /terminal/ws WebSocket endpoint to spawn a PTY and establish a…

vulnerability-analysisexploitationweb-application-exploitation+2
1 day ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

privilege-escalationreconnaissancepassword-attacks+9
3 days ago
wasm2c-tableflip preview

wasm2c-tableflip

GitHubtrustsig-eu/wasm2c-tableflip

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

vulnerability-analysisexploitationsecurity-virtualization+1
41 day ago
CVE-2026-61241 preview

CVE-2026-61241

GitHubgodliveanton/cve-2026-61241

Oracle OID LDAP Server Privileges Management Exploit

privilege-escalationexploitationnetwork-security+3
1 day ago
certighost preview

certighost

GitHubl0u7r3/certighost

Proof-of-concept exploit code for CVE-2026-54121, adapted and edited for validating the vulnerability in affected environments.

vulnerability-analysisexploitationpenetration-testing
1 day ago
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationweb-application-exploitationweb-security+3
11 day ago
CVE-2021-42013_821311 preview

CVE-2021-42013_821311

GitHubandreamammano89-maker/cve-2021-42013_821311

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

vulnerability-analysisexploitationweb-application-exploitation+1
1 day ago
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

vulnerability-analysisexploitationweb-application-exploitation+3
1 day ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

vulnerability-scannersexploitationweb-application-exploitation+3
1 day ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

vulnerability-scannersexploitationweb-application-exploitation+3
12 years ago
CVE_2019_2215 preview

CVE_2019_2215

GitHub0xbinder/cve_2019_2215

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

android-securityprivilege-escalationvulnerability-analysis+5
11 day ago
CVE-2026-64849 preview

CVE-2026-64849

GitHubbiutrap/cve-2026-64849

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

vulnerability-analysisexploitationweb-application-exploitation+4
2 days ago
CVE-2024-8068-CVE-2024-8069 preview

CVE-2024-8068-CVE-2024-8069

GitHubhorkimhab/cve-2024-8068-cve-2024-8069

Proof-of-concept exploit scripts for CVE-2024-8068 and CVE-2024-8069, focused on authorized penetration testing, educational labs, and defensive…

vulnerability-analysisexploitationpenetration-testing+2
1 day ago
CVE-2026-19598-PoC preview

CVE-2026-19598-PoC

GitHubdeadexpl0it/cve-2026-19598-poc

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

privilege-escalationvulnerability-analysisexploitation+3
2 days ago
vivo_iqoo_neo_9_root_research_on_CVE-2025-21479 preview

vivo_iqoo_neo_9_root_research_on_CVE-2025-21479

GitHubreaizuguo/vivo_iqoo_neo_9_root_research_on_cve-2025-21479

iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** — 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案

android-securityprivilege-escalationvulnerability-analysis+4
13 days ago
Previous12…1282Next