Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Vulnerability Analysis

Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

NewestRelevanceMost popularRecently updated
25175 results
CVE-2026-71518 preview

CVE-2026-71518

GitHubilhomjonr/cve-2026-71518

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

authentication-authorizationvulnerability-analysisexploitation+3
1
3 days ago
CVE-2024-40275_Scanner preview

CVE-2024-40275_Scanner

GitHubburjoy/cve-2024-40275_scanner

Scanner for CVE-2024-40725 Apache HTTP Server source-code disclosure; probes direct and subrequest paths, fingerprints affected versions, and outputs…

vulnerability-scannersweb-vulnerability-scannersvulnerability-analysis+2
3 days ago
CVE-2026-19478-PoC preview

CVE-2026-19478-PoC

GitHubdavkharrr/cve-2026-19478-poc

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

vulnerability-analysisexploitationweb-application-exploitation+3
13 days ago
ghostlock-cve-2026-43499 preview

ghostlock-cve-2026-43499

GitHubgitchw/ghostlock-cve-2026-43499

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

embedded-systems-securityprivilege-escalationiot-security+5
2 days ago
CVE-2026-19598 preview

CVE-2026-19598

GitHubksotaria1337/cve-2026-19598

Minimal Python repository for studying and reproducing a specific CVE, intended for vulnerability validation in controlled environments.

vulnerability-analysis
2 days ago
CVE-2026-44578 preview

CVE-2026-44578

GitHublxxexxbxx/cve-2026-44578

Proof-of-concept exploit for CVE-2026-44578 that reproduces the vulnerable condition, enabling security researchers to validate affected systems and…

vulnerability-analysisexploitationadversarial-attack
2 days ago
CVE-2026-20217 preview

CVE-2026-20217

GitHubsecurifera/cve-2026-20217

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

privilege-escalationvulnerability-analysisexploitation+5
3 days ago
CVE-2026-19500-poc preview

CVE-2026-19500-poc

GitHubtypedefabcd1234ntd/cve-2026-19500-poc

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

vulnerability-analysisexploitationweb-application-exploitation+1
2 days ago
CVE-2026-19501-poc preview

CVE-2026-19501-poc

GitHubtypedefabcd1234ntd/cve-2026-19501-poc

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

payload-generationvulnerability-analysisexploitation+3
2 days ago
hp-slate7-root-kit preview

hp-slate7-root-kit

GitHubvalentineus/hp-slate7-root-kit

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

android-securityprivilege-escalationpersistence-mechanisms+6
12 days ago
CVE-2025-62593-PoC preview

CVE-2025-62593-PoC

GitHubboreas37/cve-2025-62593-poc

PoC for CVE-2025-62593: unauthenticated RCE in Ray (CISA KEV). Stdlib-only Python.

vulnerability-analysisexploitationweb-application-exploitation+2
12 days ago
CVE-2025-5880 preview

CVE-2025-5880

GitHubac8999/cve-2025-5880

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

vulnerability-analysisexploitationweb-application-exploitation
2 days ago
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

authentication-authorizationcontainer-securityvulnerability-analysis+3
2 days ago
CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization preview

CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization

GitHubcypherhippie/cve-2026-34486---unauthenticated-rce-via-java-deserialization

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

payload-generationvulnerability-analysisexploitation+2
2 days ago
CVE-2024-20767-Adobe-ColdFusion preview

CVE-2024-20767-Adobe-ColdFusion

GitHubgraysignal/cve-2024-20767-adobe-coldfusion

PoC exploit for CVE-2024-20767 in Adobe ColdFusion, leveraging an improper access control flaw to read arbitrary files from affected servers.

vulnerability-analysisexploitationweb-application-exploitation+1
12 years ago
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability preview

CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability

GitHubgraysignal/cve-2024-23897-jenkins-arbitrary-read-file-vulnerability

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

vulnerability-analysisexploitationweb-application-exploitation+4
32 years ago
CVE-2024-24919-Check-Point-Remote-Access-VPN preview

CVE-2024-24919-Check-Point-Remote-Access-VPN

GitHubgraysignal/cve-2024-24919-check-point-remote-access-vpn

Scan for and exploit CVE-2024-24919 in Check Point Security Gateways, an unauthenticated arbitrary file read that can expose credentials and lead to…

vulnerability-scannersexploitationinformation-gathering+2
12 years ago
CVE-2024-28995-SolarWinds-Serv-U preview

CVE-2024-28995-SolarWinds-Serv-U

GitHubgraysignal/cve-2024-28995-solarwinds-serv-u

Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions

vulnerability-analysisexploitationweb-application-exploitation+1
12 years ago
Previous1…345…1399Next