Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Penetration Testing

Penetration testing methodologies, frameworks, reporting, and automation tools.

NewestRelevanceMost popularRecently updated
19033 results
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154 · Stored XSS in CometChat JS SDK

vulnerability-analysisexploitationweb-application-exploitation+4
3 days ago
CVE-2026-68138 preview

CVE-2026-68138

GitHubjangkrikkbozz/cve-2026-68138

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

privilege-escalationexploitationpenetration-testing+1
4 days ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubkatransefa/cve-2026-13714

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

exploitationweb-application-exploitationpost-exploitation+2
3 days ago
CVE-2023-22515 preview

CVE-2023-22515

GitHubs1incere/cve-2023-22515

Confluence Unauthorized Administrator User Addition Exploitation Script

authentication-authorizationvulnerability-analysisexploitation+3
254 months ago
Vulnarium preview

Vulnarium

GitHubzypherion-technologies/vulnarium

A security research archive documenting vulnerabilities, technical analysis, and PoC demonstrations.

privilege-escalationvulnerability-analysisexploitation+2
44 days ago
CVE-2026-59310 preview

CVE-2026-59310

GitHubhorkimhab/cve-2026-59310

Educational CVE proof-of-concept repository with lab scripts for reproducing, testing, and analyzing specific vulnerabilities in isolated…

vulnerability-analysisexploitationpenetration-testing+3
4 days ago
CVE-2026-20896-Gitea-Authentication-Bypass preview

CVE-2026-20896-Gitea-Authentication-Bypass

GitHubjudgedbykira/cve-2026-20896-gitea-authentication-bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

vulnerability-analysisexploitationweb-application-exploitation+5
5 days ago
CVE-2026-73847-emlog-PoC preview

CVE-2026-73847-emlog-PoC

GitHubsqueeze440/cve-2026-73847-emlog-poc

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
CVE-2026-6837-zyxel-export-cgi-command-injection preview

CVE-2026-6837-zyxel-export-cgi-command-injection

GitHubminanagehsalalma/cve-2026-6837-zyxel-export-cgi-command-injection

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

embedded-systems-securityvulnerability-analysisexploitation+3
4 days ago
zyxel-social-login-bypass-cve-2026-8508 preview

zyxel-social-login-bypass-cve-2026-8508

GitHubminanagehsalalma/zyxel-social-login-bypass-cve-2026-8508

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

vulnerability-analysisexploitationweb-application-exploitation+4
4 days ago
CVE-2026-9830 preview

CVE-2026-9830

GitHubopaxial/cve-2026-9830

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

vulnerability-analysisexploitationweb-application-exploitation+3
1425 days ago
CVE-2026-73633 preview

CVE-2026-73633

GitHubcuteecat/cve-2026-73633

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

vulnerability-analysisexploitationweb-application-exploitation+2
4 days ago
CVE-2026-72898-safe-detection preview

CVE-2026-72898-safe-detection

GitHubfranc-zar/cve-2026-72898-safe-detection

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

vulnerability-scannersvulnerability-analysisweb-application-exploitation+2
4 days ago
CVE-2025-11740 preview

CVE-2025-11740

GitHubalixploit22/cve-2025-11740

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

vulnerability-analysisexploitationpenetration-testing
5 days ago
CVE-2026-47103-python-statemachine-rce preview

CVE-2026-47103-python-statemachine-rce

GitHubsaiteja-erukude/cve-2026-47103-python-statemachine-rce

Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.

payload-generationvulnerability-analysisexploitation+1
5 days ago
CVE-2026-47117-openmed-rce preview

CVE-2026-47117-openmed-rce

GitHubsaiteja-erukude/cve-2026-47117-openmed-rce

OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsvulnerability-scannersweb-vulnerability-scanners+4
4 days ago
flar3ad preview

flar3ad

GitHubdaemoncibsec/flar3ad

POC of CVE-2026-51031 for arbitrary local file read

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
Previous1…456…1058Next