Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Vulnerability Analysis

Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

NewestRelevanceMost popularRecently updated
25176 results
CVE-2025-6934 preview

CVE-2025-6934

GitHubrosemary1337/cve-2025-6934

Automated PoC exploit for WordPress Opal Estate Pro that detects vulnerable versions, retrieves nonce, and creates unauthorized administrator…

vulnerability-analysisexploitationweb-application-exploitation+3
11 months ago
CVE-2026-40179-PoC preview

CVE-2026-40179-PoC

GitHubbsdrip/cve-2026-40179-poc

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

vulnerability-analysisexploitationweb-application-exploitation+1
1 day ago
CVE-2026-41089 preview

CVE-2026-41089

GitHubjelasin/cve-2026-41089

Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

vulnerability-analysisexploitationnetwork-security+3
2 months ago
CVE-2026-56848 preview

CVE-2026-56848

GitHubopen-flaw/cve-2026-56848

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

vulnerability-analysisdynamic-code-analysisexploitation+2
2 days ago
CVE-2026-47858 preview

CVE-2026-47858

GitHubrealstatus/cve-2026-47858

Proof-of-concept exploit for unauthenticated JMX RCE in Spring Tools live information mode, using MLet remote class loading to execute arbitrary…

payload-generationvulnerability-analysisexploitation+1
1 day ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubrenzi25031469/cve-2026-19478

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

web-vulnerability-scannersvulnerability-analysisweb-application-exploitation+4
1 day ago
activemq-cve-2023-46604-lab preview

activemq-cve-2023-46604-lab

GitHubstefanotractor/activemq-cve-2023-46604-lab

Hands-on lab for exploiting Apache ActiveMQ CVE-2023-46604 remote code execution, with Python-based tooling and a vulnerable environment setup.

vulnerability-analysisexploitationlabs-practice
1 day ago
cve-2026-13934 preview

cve-2026-13934

GitHubartwiderobo/cve-2026-13934

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

vulnerability-analysiscode-analysisexploitation+3
15 days ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubkaleth4/cve-2026-64638

Technical analysis and defensive mitigation for a WordPress Core pre-auth XSS-to-RCE chain, including sanitizer bypass, DOM clobbering, JSONP abuse,…

vulnerability-analysisexploitationweb-application-exploitation+3
2 days ago
CVE-2020-14882-WebLogic-Analysis preview

CVE-2020-14882-WebLogic-Analysis

GitHubvelessecurity/cve-2020-14882-weblogic-analysis

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

vulnerability-analysisexploitationweb-application-exploitation+1
2 days ago
fastgpt-sandbox-audit preview

fastgpt-sandbox-audit

GitHubqianlijaingshan/fastgpt-sandbox-audit

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

static-analysisdynamic-analysis-sandboxingvulnerability-analysis+4
2 days ago
CVE-2026-14669 preview

CVE-2026-14669

GitHubhackspeak/cve-2026-14669

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

vulnerability-analysisexploitationpenetration-testing+4
12 days ago
CVE-2021-1675-PrintNightmare-Analysis preview

CVE-2021-1675-PrintNightmare-Analysis

GitHubvelessecurity/cve-2021-1675-printnightmare-analysis

Technical write-up and analysis of PrintNightmare (CVE-2021-1675 / CVE-2021-34527), covering RCE/LPE exploitation, detection via Windows event logs,…

privilege-escalationreconnaissancevulnerability-analysis+6
2 days ago
ShieldBreak preview

ShieldBreak

GitHub1neptune/shieldbreak

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

vulnerability-analysisexploitationids-ips-evasion+1
12 days ago
CVE-2026-73292 preview

CVE-2026-73292

GitHubcamillegr/cve-2026-73292

Proof-of-concept exploit for CVE-2026-73292: CSRF attack on Semaphore UI password change endpoint, serving a malicious page that silently resets an…

vulnerability-analysisexploitationweb-application-exploitation+3
2 days ago
HeartBleed-CVE-2014-0160--SCRIPTS-python3 preview

HeartBleed-CVE-2014-0160--SCRIPTS-python3

GitHubihsspotlight/heartbleed-cve-2014-0160--scripts-python3

Python scripts for detecting and exploiting OpenSSL Heartbleed (CVE-2014-0160), leaking sensitive memory contents from vulnerable TLS services.

vulnerability-analysisexploitationnetwork-security
2 days ago
CVE-2026-70376 preview

CVE-2026-70376

GitHubilhomjonr/cve-2026-70376

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

vulnerability-analysisexploitationweb-application-exploitation+3
8 days ago
CVE-2025-69848-security-advisories preview

CVE-2025-69848-security-advisories

GitHubalkimcoskun/cve-2025-69848-security-advisories

Security advisory for CVE-2025-69848 – Reflected XSS in NetBox ProtectedError handling

vulnerability-analysisweb-securitycurated-resources
6 months ago
Previous1234…1399Next