Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Payload Development

Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

NewestRelevanceMost popularRecently updated
3295 results
CVE-2026-28134 preview

CVE-2026-28134

GitHubrandomrobbiebf/cve-2026-28134

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

vulnerability-analysisexploitationweb-application-exploitation+1
5 months ago
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationweb-application-exploitationweb-security+3
11 day ago
CVE-2026-43499_HW-CLT-AL01 preview

CVE-2026-43499_HW-CLT-AL01

GitHubzychen027/cve-2026-43499_hw-clt-al01

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

android-securityprivilege-escalationexploitation+4
2 days ago
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

persistence-mechanismsdata-exfiltrationpost-exploitation+5
3 days ago
dyen preview

dyen

GitHubcenobyte-vincit/dyen

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

payload-generationids-ips-evasionpost-exploitation+4
3 days ago
CVE-2020-14882-WebLogic-Analysis preview

CVE-2020-14882-WebLogic-Analysis

GitHubvelessecurity/cve-2020-14882-weblogic-analysis

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

vulnerability-analysisexploitationweb-application-exploitation+1
2 days ago
CVE-2026-14669 preview

CVE-2026-14669

GitHubhackspeak/cve-2026-14669

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

vulnerability-analysisexploitationpenetration-testing+4
12 days ago
ghostlock-cve-2026-43499 preview

ghostlock-cve-2026-43499

GitHubgitchw/ghostlock-cve-2026-43499

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

embedded-systems-securityprivilege-escalationiot-security+5
2 days ago
hp-slate7-root-kit preview

hp-slate7-root-kit

GitHubvalentineus/hp-slate7-root-kit

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

android-securityprivilege-escalationpersistence-mechanisms+6
12 days ago
CVE-2026-33017-FireFlow preview

CVE-2026-33017-FireFlow

GitHubl4st98/cve-2026-33017-fireflow

Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

exploitationweb-application-exploitationctf+4
3 days ago
cve-2026-41042 preview

cve-2026-41042

GitHublulztigre/cve-2026-41042

Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…

vulnerability-analysisexploitationweb-application-exploitation+2
3 days ago
CVE-2026-20079 preview

CVE-2026-20079

GitHubcyberauth/cve-2026-20079

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

vulnerability-analysisexploitationweb-application-exploitation+3
3 days ago
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154 · Stored XSS in CometChat JS SDK

vulnerability-analysisexploitationweb-application-exploitation+4
3 days ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubkatransefa/cve-2026-13714

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

exploitationweb-application-exploitationpost-exploitation+2
3 days ago
CVE-2026-17544 preview

CVE-2026-17544

GitHubr2qa/cve-2026-17544

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

vulnerability-analysisexploitationweb-application-exploitation+4
5 days ago
POC-GeoLeak-CVE-2026-52715 preview

POC-GeoLeak-CVE-2026-52715

GitHub686f6c61/poc-geoleak-cve-2026-52715

PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit…

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
MouseServer-1.7.8.5-RCE preview

MouseServer-1.7.8.5-RCE

GitHubmermehr/mouseserver-1.7.8.5-rce

PoC exploit for CVE-2022-3218 targeting WiFi Mouse Server 1.7.8.5, achieving RCE via keystroke injection and in-memory PowerShell payload delivery…

vulnerability-analysisexploitationpenetration-testing+2
5 days ago
CVE-2025-64512-pdfminer-PoC preview

CVE-2025-64512-pdfminer-PoC

GitHuboguzylmzx/cve-2025-64512-pdfminer-poc

PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted PDF

payload-generationvulnerability-analysisexploitation+3
5 days ago
Previous12…184Next